Impact
The vulnerability lies in the IronVNC client bundled with Devolutions Remote Desktop Manager. It fails to verify the authenticity of the server’s RSA key during RSA‑AES authentication, allowing an on‑path attacker to intercept and modify VNC traffic. An attacker who can position themselves between the client and the target VNC server can force the client to accept a forged key, thereby gaining full control over the session and the data it transports.
Affected Systems
Devolutions Remote Desktop Manager, versions 2026.2.17.0 and earlier and 2026.1.24.0 and earlier, are affected. The flaw is specifically located in the embedded IronVNC client component used for remote desktop connections.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity. The flaw—automatic acceptance of an unverified RSA key—enables a man‑in‑the‑middle attacker to tamper with or eavesdrop on VNC sessions. An attacker only needs to intercept the network channel; no credentials or special privileges are required beyond that. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. Despite the moderate CVSS rating, the straightforward network attack vector and the potential impact on confidentiality and integrity make this vulnerability a concern for environments that rely on Remote Desktop Manager for critical remote access.
OpenCVE Enrichment