PT-2025-19709 · Devolutions · Devolutions Server

CVE-2025-4316

·

Publicado

2025-05-05

·

Atualizado

2025-05-05

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.1.6.0 and earlier
Description The issue is related to improper access control in the PAM feature, allowing a PAM user to self-approve their PAM requests even if disallowed by the configured policy. This can be achieved via specific user interface actions.
Recommendations For Devolutions Server versions 2025.1.6.0 and earlier, consider restricting access to the PAM feature until a patch is available, or apply specific configuration changes to the user interface to prevent self-approval of PAM requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-15267
CVE-2025-4316

Produtos afetados

Devolutions Server