Vulnerabilidades em Devolutions

176 resultados
Análise Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2023-2282LOWImproper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticEPSS 0.4%CVE-2024-2403MEDIUM Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attaEPSS 0.4%CVE-2026-2590CRITICALImproper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop ManaEPSS 0.4%CVE-2025-6523CRITICALUse of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatEPSS 0.4%CVE-2025-11958MEDIUMAn improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticatEPSS 0.4%CVE-2025-2562MEDIUMInsufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a storedEPSS 0.4%CVE-2023-1939MEDIUMNo access control for the OTP key on OTP entriesEPSS 0.4%CVE-2024-2241MEDIUMImproper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintendEPSS 0.4%CVE-2025-12808MEDIUMImproper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custoEPSS 0.4%CVE-2025-2600MEDIUMImproper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEPSS 0.4%CVE-2025-8353MEDIUMUI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a rEPSS 0.4%CVE-2025-2499MEDIUMClient side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can eEPSS 0.4%CVE-2025-5382MEDIUMImproper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to rEPSS 0.4%CVE-2025-1193HIGHImproper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows aEPSS 0.4%CVE-2025-13683MEDIUMExposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions ServeEPSS 0.4%CVE-2024-4846MEDIUMAuthentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to aEPSS 0.4%CVE-2022-1342A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching EPSS 0.4%CVE-2025-6741HIGHImproper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via theEPSS 0.4%CVE-2024-12148MEDIUMIncorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to acceEPSS 0.4%CVE-2025-13765MEDIUMExposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: beEPSS 0.4%