Improper Access Controls in Devolutions Server by Devolutions
CVE-2023-0952

6.5MEDIUM

Key Information:

Vendor
CVE Published:
1 March 2023

What is CVE-2023-0952?

Improper access controls in Devolutions Server versions 2022.3.12 and earlier could potentially enable an authenticated user to gain unauthorized access to sensitive information. This vulnerability highlights the importance of robust access control measures to prevent unauthorized data exposure. For detailed insights, refer to the security advisory from Devolutions.

Affected Version(s)

Devolutions Server 0 <= 2022.3.12

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.