Cyber Resilience

CVE-2023-5765

Devolutions Remote Desktop Manager ≤ 2023.2.33

Published
01 November 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0061 46th percentile
Risk Priority 72 floored blend · peak EPSS

Summary

CVE-2023-5765 is a critical-severity an unspecified weakness vulnerability in Devolutions Remote Desktop Manager. Its CVSS base score is 9.8 (Critical).

Operationally, ranked at the 46th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-4417Same product: Devolutions Remote Desktop Manager
CVE-2023-7047Same product: Devolutions Remote Desktop Manager
CVE-2023-2282Same product: Devolutions Remote Desktop Manager
CVE-2024-0589Same product: Devolutions Remote Desktop Manager
CVE-2023-5766Same product: Devolutions Remote Desktop Manager
CVE-2023-2257Same product: Microsoft Windows
CVE-2023-36868Same product: Microsoft Windows
CVE-2024-20670Same product: Microsoft Windows
CVE-2024-6913Same product: Microsoft Windows
CVE-2023-23459Same product: Microsoft Windows

Affected Assets

devolutions
remote desktop manager
≤ 2023.2.33

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References