Security & Compliance
DEVO-2025-0012
Summary
Devolutions Server is affected by multiple vulnerabilities.
Affected Products
Devolutions Server 2025.2.4 and earlier
Change Log
22/7/2025 - Initial publication
Severity
High
Products
Devolutions Server
Fix Version
2025.2.5.0
Improper access control in secure message component in Devolutions Server
Description
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature.
Remediation and Workarounds
Upgrade to Devolutions Server 2025.2.5.0 or higher
Severity
7.1 High - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
- Devolutions Server 2025.2.2.0 through 2025.2.4.0
- Devolutions Server 2025.1.11.0 and earlier
CVE(s)
CVE-2025-6741
Use of weak credentials in emergency authentication component in Devolutions Server
Description
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe.
Remediation and Workarounds
Upgrade to Devolutions Server 2025.2.4.0 or higher
Severity
9.5 Critical - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
Affected Products
- Devolutions Server 2025.2.2.0 through 2025.2.3.0
- Devolutions Server 2025.1.11.0 and earlier
CVE(s)
CVE-2025-6523