CVE-2024-3545
Estado: AnalizadaMedia (4.3)—
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-281
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3545",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3545",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-04-10T19:14:58.719678Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "security@devolutions.net",
"affectedData": [
{
"vendor": "Devolutions",
"product": "Server",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2024.1.8.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Devolutions",
"product": "Remote Desktop Manager",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2024.1.20.0"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-04-09T19:15:41.380",
"references": [
{
"url": "https://devolutions.net/security/advisories/DEVO-2024-0006",
"tags": [
"Vendor Advisory"
],
"source": "security@devolutions.net"
},
{
"url": "https://devolutions.net/security/advisories/DEVO-2024-0006",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-281"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.\n\n"
},
{
"lang": "es",
"value": "El manejo inadecuado de permisos en la función de caché fuera de línea de vault en Devolutions Remote Desktop Manager 2024.1.20 y versiones anteriores en Windows y Devolutions Server 2024.1.8 y versiones anteriores permite a un atacante acceder a información confidencial contenida en el archivo de caché fuera de línea obteniendo acceso a una computadora donde el software está instalado aunque el modo sin conexión esté desactivado."
}
],
"lastModified": "2026-06-17T07:44:29.313",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C6B1BE5-9C13-4FB3-9FD9-5C07895EB64A",
"versionEndExcluding": "2024.1.9.0"
},
{
"criteria": "cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "A0A4A4C4-D82F-482A-BD3B-C81751B7B7AB",
"versionEndExcluding": "2024.1.21.0"
},
{
"criteria": "cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "7B36BC3F-784D-4AC7-9224-6CD59EC6AC6F",
"versionEndExcluding": "2024.1.21.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@devolutions.net"
}