Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2025-0003
Devolutions Server is affected by a vulnerability.
Affected Products
Change Log
5/3/2025 - Initial publication
Incorrect authorization in PAM vaults
Medium 6.0 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.
CVE(s)
CVE-2025-2003