Lucene search

K
vulnrichmentDEVOLUTIONSVULNRICHMENT:CVE-2024-6354
HistoryJun 26, 2024 - 4:20 p.m.

CVE-2024-6354

2024-06-2616:20:42
DEVOLUTIONS
github.com
3
improper access control
pam dashboard
devolutions remote desktop manager 2024.2.11
windows
authenticated user
bypass execute permission

AI Score

7

Confidence

Low

EPSS

0

Percentile

9.1%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:devolutions:remote_desktop_manager:-:*:*:*:*:*:*:*"
    ],
    "vendor": "devolutions",
    "product": "remote_desktop_manager",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "2024.2.11"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

7

Confidence

Low

EPSS

0

Percentile

9.1%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-6354