Missing certificate validation in Devolutions Remote...
High severity
Unreviewed
Published
Feb 10, 2025
to the GitHub Advisory Database
•
Updated Feb 10, 2025
Description
Published by the National Vulnerability Database
Feb 10, 2025
Published to the GitHub Advisory Database
Feb 10, 2025
Last updated
Feb 10, 2025
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack.
Versions affected are :
Remote Desktop Manager macOS 2024.3.9.0 and earlier
Remote Desktop Manager Linux 2024.3.2.5 and earlier
Remote Desktop Manager Android 2024.3.3.7 and earlier
Remote Desktop Manager iOS 2024.3.3.0 and earlier
Remote Desktop Manager Powershell 2024.3.6.0 and earlier
References