Access Control Vulnerability in Devolutions Server
CVE-2025-5382

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 June 2025

What is CVE-2025-5382?

An access control vulnerability exists in the Multi-Factor Authentication (MFA) feature of Devolutions Server versions 2025.1.7.0 and earlier. This issue enables users with management permissions to potentially modify or revoke the MFA settings of administrators. Such actions can undermine the overall security posture of the system, making it crucial for organizations to rectify this vulnerability by applying the necessary updates and securing user permissions.

Affected Version(s)

Server 0 <= 2025.1.7.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5382 : Access Control Vulnerability in Devolutions Server