CVE-2023-1939: Devolutions Remote Desktop Manager
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
Affected products
- Devolutions Remote Desktop Manager: up to and including 2022.3.2.0; up to and including 2022.3.33.0
Published 2023-04-11. Last modified 2026-06-17.