CVE-2022-3781
Severity CVSS v4.0:
Pending analysis
Type:
CWE-311
Missing Encryption of Sensitive Data
Publication date:
01/11/2022
Last modified:
05/05/2025
Description
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data.<br />
<br />
This issue affects : <br />
Remote Desktop Manager 2022.2.26 and prior versions.<br />
<br />
Devolutions Server 2022.3.1 and prior versions.<br />
<br />
<br />
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | 2022.3.2 (excluding) | |
| cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:* | 2022.2.27 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



