Vulnerability Details CVE-2024-6354
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.6%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2024-6354
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.15.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.17.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.18.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.19.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.20.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.21.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.23.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.25.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.27.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.28.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.29.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.30.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.31.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.1.32.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.2.10.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.2.11.0
-
cpe:2.3:a:devolutions:remote_desktop_manager:2024.2.8.0