Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack.
Versions affected are :
Remote Desktop Manager macOS 2024.3.9.0 and earlier
Remote Desktop Manager Linux 2024.3.2.5 and earlier
Remote Desktop Manager Android 2024.3.3.7 and earlier
Remote Desktop Manager iOS 2024.3.3.0 and earlier
Remote Desktop Manager Powershell 2024.3.6.0 and earlier
References
Link | Resource |
---|---|
https://devolutions.net/security/advisories/DEVO-2025-0001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
28 Mar 2025, 16:20
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Devolutions remote Desktop Manager
Devolutions Devolutions remote Desktop Manager Powershell |
|
References | () https://devolutions.net/security/advisories/DEVO-2025-0001/ - Vendor Advisory | |
CPE | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:macos:*:* cpe:2.3:a:devolutions:remote_desktop_manager_powershell:*:*:*:*:*:*:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:android:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:linux:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:iphone_os:*:* |
10 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
10 Feb 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-10 14:15
Updated : 2025-03-28 16:20
NVD link : CVE-2024-11621
Mitre link : CVE-2024-11621
CVE.ORG link : CVE-2024-11621
JSON object : View
Products Affected
devolutions
- remote_desktop_manager
- remote_desktop_manager_powershell
CWE
CWE-295
Improper Certificate Validation