{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-1202","assignerOrgId":"bfee16bd-18e6-446c-9a65-f5b2e3d89c23","state":"PUBLISHED","assignerShortName":"DEVOLUTIONS","dateReserved":"2023-03-06T15:52:04.023Z","datePublished":"2023-03-23T17:12:47.824Z","dateUpdated":"2025-02-20T20:54:27.768Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Remote Desktop Manager","vendor":"Devolutions","versions":[{"lessThanOrEqual":"2023.1.9","status":"affected","version":"0","versionType":"custom"}]}],"datePublic":"2023-03-23T17:12:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Permission bypass when importing or synchronizing entries<span style=\"background-color: rgb(255, 255, 255);\">&nbsp;in User vault</span>\n\n in Devolutions Remote Desktop Manager 2023.1.9 and <span style=\"background-color: rgb(255, 255, 255);\">prior versions </span>allows users with restricted rights to bypass entry permission via id collision."}],"value":"Permission bypass when importing or synchronizing entries in User vault\n\n in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision."}],"providerMetadata":{"orgId":"bfee16bd-18e6-446c-9a65-f5b2e3d89c23","shortName":"DEVOLUTIONS","dateUpdated":"2023-04-02T18:49:20.069Z"},"references":[{"url":"https://devolutions.net/security/advisories/DEVO-2023-0008"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"},"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T05:40:58.190Z"},"title":"CVE Program Container","references":[{"url":"https://devolutions.net/security/advisories/DEVO-2023-0008","tags":["x_transferred"]}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-863","lang":"en","description":"CWE-863 Incorrect Authorization"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":6.5,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-02-20T20:50:30.931746Z","id":"CVE-2023-1202","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-20T20:54:27.768Z"}}]}}