CVE-2025-5334
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/05/2025
Last modified:
02/07/2025
Description
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager<br />
allows an authenticated user to gain unauthorized access to private personal information. <br />
<br />
<br />
<br />
Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.<br />
<br />
<br />
<br />
<br />
This issue affects the following versions :<br />
<br />
* Remote Desktop Manager Windows 2025.1.34.0 and earlier<br />
* <br />
Remote Desktop Manager macOS 2025.1.16.3 and earlier<br />
<br />
<br />
<br />
* <br />
Remote Desktop Manager Android 2025.1.3.3 and earlier<br />
* <br />
Remote Desktop Manager iOS 2025.1.6.0 and earlier
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:-:macos:*:* | 2025.1.16.3 (including) | |
| cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:* | 2025.1.37.0 (excluding) | |
| cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:* | 2025.1.37.0 (excluding) | |
| cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:-:iphone_os:*:* | 2025.2.0.0 (excluding) | |
| cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:-:android:*:* | 2025.2.0.17 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



