Access Control Flaw in Devolutions Server 2024.3.13 and Earlier
CVE-2025-2278

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 March 2025

What is CVE-2025-2278?

An improper access control vulnerability exists in the temporary access requests and checkout requests endpoints of Devolutions Server versions 2024.3.13 and earlier. This flaw permits an authenticated user to gain unauthorized access to sensitive information related to these requests by exploiting a known request ID, potentially leading to data exposure and security breaches.

Affected Version(s)

Server 0 <= 2024.3.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.