Description
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Published: 2026-08-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Man‑in‑the‑middle tampering of VNC sessions
Action: Patch Now
AI Analysis

Impact

The vulnerability lies in the IronVNC client bundled with Devolutions Remote Desktop Manager. It fails to verify the authenticity of the server’s RSA key during RSA‑AES authentication, allowing an on‑path attacker to intercept and modify VNC traffic. An attacker who can position themselves between the client and the target VNC server can force the client to accept a forged key, thereby gaining full control over the session and the data it transports.

Affected Systems

Devolutions Remote Desktop Manager, versions 2026.2.17.0 and earlier and 2026.1.24.0 and earlier, are affected. The flaw is specifically located in the embedded IronVNC client component used for remote desktop connections.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate severity. The flaw—automatic acceptance of an unverified RSA key—enables a man‑in‑the‑middle attacker to tamper with or eavesdrop on VNC sessions. An attacker only needs to intercept the network channel; no credentials or special privileges are required beyond that. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. Despite the moderate CVSS rating, the straightforward network attack vector and the potential impact on confidentiality and integrity make this vulnerability a concern for environments that rely on Remote Desktop Manager for critical remote access.

Generated by OpenCVE AI on August 28, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest version of Remote Desktop Manager that includes the RSA key verification fix.
  • If an upgrade cannot be performed immediately, configure the client to require manual RSA key acceptance or disable automatic RSA key acceptance to enforce authentication.
  • Restrict VNC traffic to a protected VPN or dedicated secure channel so that only trusted network elements can interpose on the connection.

Generated by OpenCVE AI on August 28, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title On-Path Attacker Can Tamper with VNC Sessions via Unverified RSA Key Acceptance

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title On-Path Attacker Can Tamper with VNC Sessions via Unverified RSA Key Acceptance

Mon, 24 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
Vendors & Products Devolutions
Devolutions remote Desktop Manager

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Weaknesses CWE-345
References

Subscriptions

Devolutions Remote Desktop Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-08-28T17:33:51.985Z

Reserved: 2026-08-24T15:10:53.447Z

Link: CVE-2026-78417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T19:17:04.420

Modified: 2026-08-28T20:19:57.820

Link: CVE-2026-78417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity