Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2024-0016 |
History
Mon, 25 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 25 Nov 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching. | |
Weaknesses | CWE-287 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2024-11-25T14:46:42.687Z
Updated: 2024-11-25T16:47:10.705Z
Reserved: 2024-11-25T14:27:39.742Z
Link: CVE-2024-11671
Vulnrichment
Updated: 2024-11-25T16:47:06.569Z
NVD
Status : Received
Published: 2024-11-25T15:15:07.040
Modified: 2024-11-25T17:15:11.930
Link: CVE-2024-11671
Redhat
No data.