---
cve: "CVE-2023-6588"
severity: "LOW"
cvss: 3.1
epss: "59%"
vendor: "Devolutions"
kev: false
exploited: false
published: "2023-12-07 16:15:07"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T11:58:52+02:00"
---

# CVE-2023-6588

> 3.1 LOW

## Beschreibung

Offline mode is always enabled, even if permission disallows it, in 
Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and 
earlier. This allows an attacker with access to the Workspace 
application to access credentials when offline.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://devolutions.net/security/advisories/DEVO-2023-0022/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-6588) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
