{"api_version":"1","generated_at":"2026-07-23T21:43:04+00:00","cve":"CVE-2023-1939","urls":{"html":"https://cve.report/CVE-2023-1939","api":"https://cve.report/api/cve/CVE-2023-1939.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1939","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1939"},"summary":{"title":"CVE-2023-1939","description":"No access control for the OTP key \n\n on OTP entries\n\n in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.","state":"PUBLIC","assigner":"security@devolutions.net","published_at":"2023-04-11 18:15:00","updated_at":"2023-04-21 17:59:00"},"problem_types":["CWE-732"],"metrics":[],"references":[{"url":"https://devolutions.net/security/advisories/DEVO-2023-0009","name":"https://devolutions.net/security/advisories/DEVO-2023-0009","refsource":"MISC","tags":[],"title":"DEVO-2023-0009 - Devolutions","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1939","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1939","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"1939","vulnerable":"1","versionEndIncluding":"2022.3.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"devolutions","cpe5":"remote_desktop_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1939","vulnerable":"1","versionEndIncluding":"2022.3.33.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"devolutions","cpe5":"remote_desktop_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-1939","ASSIGNER":"security@devolutions.net","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"No access control for the OTP key \n\n on OTP entries\n\n in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Devolutions","product":{"product_data":[{"product_name":"Remote Desktop Manager","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"2022.3.34.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://devolutions.net/security/advisories/DEVO-2023-0009","refsource":"MISC","name":"https://devolutions.net/security/advisories/DEVO-2023-0009"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2023-04-11 18:15:00","lastModifiedDate":"2023-04-21 17:59:00","problem_types":["CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:linux:*:*","versionEndIncluding":"2022.3.2.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:*","versionEndIncluding":"2022.3.33.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}