CVE Vulnerabilities

CVE-2024-11621

Improper Certificate Validation

Published: Feb 10, 2025 | Modified: Mar 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack.

Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier

Remote Desktop Manager Powershell 2024.3.6.0 and earlier

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Remote_desktop_manager Devolutions * 2024.3.2.9 (excluding)
Remote_desktop_manager Devolutions * 2024.3.4.0 (excluding)
Remote_desktop_manager Devolutions * 2024.3.4.2 (excluding)
Remote_desktop_manager Devolutions * 2024.3.10.3 (excluding)
Remote_desktop_manager_powershell Devolutions * 2024.3.7 (excluding)

Potential Mitigations

References