Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2024-0016 |
|
History
Fri, 28 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions remote Desktop Manager |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:* |
|
| Vendors & Products |
Devolutions
Devolutions remote Desktop Manager |
Mon, 25 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 25 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching. | |
| Weaknesses | CWE-287 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2024-11-25T14:46:42.687Z
Updated: 2024-11-25T16:47:10.705Z
Reserved: 2024-11-25T14:27:39.742Z
Link: CVE-2024-11671
Updated: 2024-11-25T16:47:06.569Z
Status : Analyzed
Published: 2024-11-25T15:15:07.040
Modified: 2025-03-28T16:21:57.537
Link: CVE-2024-11671
No data.