Vulnerabilities > Devolutions > High

DATE CVE VULNERABILITY TITLE RISK
2022-09-13 CVE-2022-3182 Unspecified vulnerability in Devolutions Remote Desktop Manager
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock.
local
high complexity
devolutions
7.0
2022-07-07 CVE-2022-33996 Incorrect Default Permissions vulnerability in Devolutions Server
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
network
low complexity
devolutions CWE-276
8.8
2022-06-21 CVE-2022-33995 Path Traversal vulnerability in Devolutions Remote Desktop Manager
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
network
low complexity
devolutions CWE-22
7.5
2021-10-18 CVE-2021-42098 Incorrect Default Permissions vulnerability in Devolutions Remote Desktop Manager
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.
network
low complexity
devolutions CWE-276
8.8
2021-04-14 CVE-2021-28157 SQL Injection vulnerability in Devolutions Server
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
network
low complexity
devolutions CWE-89
7.2
2021-04-01 CVE-2021-23924 Information Exposure Through Log Files vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-532
7.5
2021-04-01 CVE-2021-23923 Improper Authentication vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-287
8.1
2021-01-26 CVE-2020-36211 Improper Synchronization vulnerability in Devolutions Gfwx 0.1.0/0.2.0
An issue was discovered in the gfwx crate before 0.3.0 for Rust.
local
high complexity
devolutions CWE-662
7.0