CVE-2025-1636

Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:*

History

28 Mar 2025, 16:20

Type Values Removed Values Added
First Time Devolutions
Devolutions remote Desktop Manager
CPE cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:*
CWE NVD-CWE-noinfo
References () https://devolutions.net/security/advisories/DEVO-2025-0004/ - () https://devolutions.net/security/advisories/DEVO-2025-0004/ - Vendor Advisory

13 Mar 2025, 18:15

Type Values Removed Values Added
Summary Exposure of sensitive information in My Personnal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personnal Credentials in a shared vault via the clear history feature due to faulty business logic. Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.

13 Mar 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 13:15

Updated : 2025-03-28 16:20


NVD link : CVE-2025-1636

Mitre link : CVE-2025-1636


JSON object : View

Products Affected

devolutions

  • remote_desktop_manager