No access control for the OTP key
on OTP entries
in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
References
Link | Resource |
---|---|
https://devolutions.net/security/advisories/DEVO-2023-0009 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Apr 2023, 17:59
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-11 18:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-1939
Mitre link : CVE-2023-1939
CVE.ORG link : CVE-2023-1939
JSON object : View
Products Affected
devolutions
- remote_desktop_manager
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource