CVE-2023-6588
Status: ModifiedMedium (6.5)—
Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.59%
- Percentile among all scored CVEs: 46
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-6588",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@devolutions.net",
"affectedData": [
{
"vendor": "Devolutions",
"modules": [
"Offline Mode",
"Devolutions Server Data Source"
],
"product": "Workspace",
"versions": [
{
"status": "affected",
"version": "0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-07T16:15:07.727",
"references": [
{
"url": "https://devolutions.net/security/advisories/DEVO-2023-0022/",
"tags": [
"Vendor Advisory"
],
"source": "security@devolutions.net"
},
{
"url": "https://devolutions.net/security/advisories/DEVO-2023-0022/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\n\n\nOffline mode is always enabled, even if permission disallows it, in \nDevolutions Server data source in Devolutions Workspace 2023.3.2.0 and \nearlier. This allows an attacker with access to the Workspace \napplication to access credentials when offline.\n\n\n\n\n"
},
{
"lang": "es",
"value": "El modo sin conexión siempre está habilitado, incluso si el permiso no lo permite, en la fuente de datos del servidor de Devolutions en Devolutions Workspace 2023.3.2.0 y versiones anteriores. Esto permite que un atacante con acceso a la aplicación Workspace acceda a las credenciales cuando esté desconectado."
}
],
"lastModified": "2026-06-17T06:51:02.773",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:devolutions:workspace:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "749703AF-A1F3-4405-8677-EF10330FEC7B",
"versionEndIncluding": "2023.3.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@devolutions.net"
}