Lucene search

K
cvelistDEVOLUTIONSCVELIST:CVE-2023-2257
HistoryApr 24, 2023 - 6:48 p.m.

CVE-2023-2257

2023-04-2418:48:52
DEVOLUTIONS
www.cve.org
1
authentication
bypass
hub business
devolutions workspace desktop
vulnerability
windows
macos
force login
security
feature
locked workspace application

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub
Business space without being prompted to enter the password via an
unimplemented β€œForce Login” security feature.

This vulnerability occurs only if β€œForce Login” feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Hub Business Integration"
    ],
    "platforms": [
      "Windows",
      "MacOS"
    ],
    "product": "Workspace Desktop",
    "vendor": "Devolutions",
    "versions": [
      {
        "lessThanOrEqual": "2023.1.1.3",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVELIST:CVE-2023-2257