Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3781

Опубликовано: 01 нояб. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data.

This issue affects : Remote Desktop Manager 2022.2.26 and prior versions.

Devolutions Server 2022.3.1 and prior versions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Версия до 2022.3.2 (исключая)
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
Версия до 2022.2.27 (исключая)

EPSS

Процентиль: 28%
0.001
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-311
CWE-522

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.

EPSS

Процентиль: 28%
0.001
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-311
CWE-522