Security & Compliance

DEVO-2024-0015

Summary

Devolutions Server is affected by a vulnerability.

Affected Products

Devolutions Server 2024.3.6 and earlier

Change Log

2024-11-12 - - Initial publication

Severity

High

Product

Devolutions Server

Fix Version

DVLS 2024.3.7

Improper access control in the Password History

Description

Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.

Remediation and Workarounds

Upgrade to DVLS 2024.3.7.0 or higher

Severity

5.3 medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

DVLS 2024.3.6 and earlier

CVE(s)

CVE-2024-10971