CVE-2026-78417
N/A
N/A
Summary
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Remote Desktop Manager | 0 < 2026.2.18 | affected |
| Devolutions | Remote Desktop Manager | 0 < 2026.1.25 | affected |
Weaknesses
- CWE-345: CWE-345 Insufficient Verification of Data Authenticity
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.