PAM Password Rotation Vulnerability Allows Denial of Service
CVE-2024-1901

Currently unrated

Key Information:

Status
Vendor
CVE Published:
5 March 2024

What is CVE-2024-1901?

A denial of service vulnerability exists in Devolutions Server affecting the PAM password rotation functionality during the check-in process. Authenticated users with specific PAM permissions may exploit this vulnerability to render PAM credentials unavailable, potentially impacting system availability and user access. It is crucial for users of Devolutions Server 2023.3.14.0 to evaluate their configurations and implement the necessary security measures to mitigate the risk.

Affected Version(s)

Server 0 <= 2023.3.14.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.