Sensitive Information Exposure in Devolutions Remote Desktop Manager by Devolutions
CVE-2025-1635
6.5MEDIUM
What is CVE-2025-1635?
The Devolutions Remote Desktop Manager contains a vulnerability that allows for the unintended exposure of sensitive information during the hub data source export process. Specifically, the flaw stems from a misalignment in business logic where an authenticated user's session information could be improperly included in the exported data. This could potentially lead to unauthorized access to sensitive information, highlighting the need for users to ensure they are using the latest version to mitigate risks.
Affected Version(s)
Remote Desktop Manager Windows 0 <= 2024.3.29.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved