CVE-2024-11621

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:linux:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:android:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:macos:*:*
cpe:2.3:a:devolutions:remote_desktop_manager_powershell:*:*:*:*:*:*:*:*

History

28 Mar 2025, 16:20

Type Values Removed Values Added
Summary
  • (es) La falta de validación de certificados en Devolutions Remote Desktop Manager en macOS, iOS, Android y Linux permite que un atacante intercepte y modifique las comunicaciones cifradas mediante un ataque de intermediario. Las versiones afectadas son: Remote Desktop Manager macOS 2024.3.9.0 y anteriores Remote Desktop Manager Linux 2024.3.2.5 y anteriores Remote Desktop Manager Android 2024.3.3.7 y anteriores Remote Desktop Manager iOS 2024.3.3.0 y anteriores Remote Desktop Manager Powershell 2024.3.6.0 y anteriores
First Time Devolutions remote Desktop Manager
Devolutions
Devolutions remote Desktop Manager Powershell
References () https://devolutions.net/security/advisories/DEVO-2025-0001/ - () https://devolutions.net/security/advisories/DEVO-2025-0001/ - Vendor Advisory
CPE cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:macos:*:*
cpe:2.3:a:devolutions:remote_desktop_manager_powershell:*:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:android:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:linux:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:iphone_os:*:*

10 Feb 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

10 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 14:15

Updated : 2025-03-28 16:20


NVD link : CVE-2024-11621

Mitre link : CVE-2024-11621

CVE.ORG link : CVE-2024-11621


JSON object : View

Products Affected

devolutions

  • remote_desktop_manager
  • remote_desktop_manager_powershell
CWE
CWE-295

Improper Certificate Validation