CVE-2023-6593

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*

History

15 Dec 2023, 14:38

Type Values Removed Values Added
Summary
  • (es) La omisión de permisos del lado del cliente en Devolutions Remote Desktop Manager 2023.3.4.0 y versiones anteriores en iOS permite a un atacante que tiene acceso a la aplicación ejecutar entradas en una fuente de datos SQL sin restricciones.
References () https://devolutions.net/security/advisories/DEVO-2023-0023/ - () https://devolutions.net/security/advisories/DEVO-2023-0023/ - Vendor Advisory
First Time Apple
Apple iphone Os
Devolutions remote Desktop Manager
Devolutions
CPE cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
CWE CWE-732
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

12 Dec 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 15:15

Updated : 2023-12-15 14:38


NVD link : CVE-2023-6593

Mitre link : CVE-2023-6593

CVE.ORG link : CVE-2023-6593


JSON object : View

Products Affected

devolutions

  • remote_desktop_manager

apple

  • iphone_os
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource