Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NDevolutions Remote Desktop Manager
APPDevolutions< 2024.3.31.02025.1.24.0 – 2025.1.26.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-2590CRITICAL9.8PL ✓same product
Błędne egzekwowanie zakazu zapisywania haseł w Devolutions Remote Desktop Manager
CVE-2024-6057CRITICAL9.8PL ✓same product
Pominięcie hasła master vault w Devolutions Remote Desktop Manager
CVE-2023-6593CRITICAL9.8PL ✓same product
Pomijanie uprawnień po stronie klienta w Devolutions Remote Desktop Manager na iOS
CVE-2023-5765CRITICAL9.8PL ✓same product
Nieprawidłowa kontrola dostępu w Remote Desktop Manager — obejście uprawnień
CVE-2023-5766CRITICAL9.8PL ✓same product
RCE w Remote Desktop Manager — atak przez spreparowany pakiet TCP