Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6588


Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.


Published

2023-12-07T16:15:07.727

Last Modified

2024-11-21T08:44:09.543

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application devolutions workspace ≤ 2023.3.2.0 Yes

References