MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2025-0003

Devolutions Server is affected by a vulnerability.

Affected Products

Devolutions Server
2024.3.12 and earlier

Change Log

5/3/2025 - Initial publication

Incorrect authorization in PAM vaults

Medium 6.0 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.

CVE(s)

CVE-2025-2003