CVE-2024-3545
MEDIUMDescription
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.
Is your site exposed to CVE-2024-3545?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| devolutions | devolutions_server |
| devolutions | remote_desktop_manager |
| devolutions | remote_desktop_manager |
References
Frequently Asked Questions
What is CVE-2024-3545? +
How severe is CVE-2024-3545? +
What products are affected by CVE-2024-3545? +
How do I check if I'm vulnerable to CVE-2024-3545? +
Related Vulnerabilities
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php. This issue …
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …
Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php. This …
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …