CVE-2023-6593

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*

History

15 Dec 2023, 14:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-732
CPE cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
References () https://devolutions.net/security/advisories/DEVO-2023-0023/ - () https://devolutions.net/security/advisories/DEVO-2023-0023/ - Vendor Advisory

12 Dec 2023, 15:52

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 15:15

Updated : 2024-02-05 00:22


NVD link : CVE-2023-6593

Mitre link : CVE-2023-6593

CVE.ORG link : CVE-2023-6593


JSON object : View

Products Affected

apple

  • iphone_os

devolutions

  • remote_desktop_manager
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource