Vulnerability Description
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Devolutions | Remote Desktop Manager | < 2024.3.2.9 |
| Devolutions | Remote Desktop Manager Powershell | < 2024.3.7 |
Related Weaknesses (CWE)
References
- https://devolutions.net/security/advisories/DEVO-2025-0001/Vendor Advisory
FAQ
What is CVE-2024-11621?
CVE-2024-11621 is a vulnerability with a CVSS score of 8.8 (HIGH). Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. ...
How severe is CVE-2024-11621?
CVE-2024-11621 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-11621?
Check the references section above for vendor advisories and patch information. Affected products include: Devolutions Remote Desktop Manager, Devolutions Remote Desktop Manager Powershell.