Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2025-0004/ |
![]() ![]() |
History
Tue, 18 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 13 Mar 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Exposure of sensitive information in My Personnal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personnal Credentials in a shared vault via the clear history feature due to faulty business logic. | Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic. |
Thu, 13 Mar 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Exposure of sensitive information in My Personnal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personnal Credentials in a shared vault via the clear history feature due to faulty business logic. | |
Weaknesses | CWE-200 | |
References |
|

Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-03-13T12:47:13.034Z
Updated: 2025-03-18T16:20:55.598Z
Reserved: 2025-02-24T16:29:56.376Z
Link: CVE-2025-1636

Updated: 2025-03-18T16:20:34.800Z

Status : Awaiting Analysis
Published: 2025-03-13T13:15:46.970
Modified: 2025-03-18T17:15:45.263
Link: CVE-2025-1636

No data.