PT-2025-19709 · Devolutions · Devolutions Server
CVE-2025-4316
·
Publicado
2025-05-05
·
Atualizado
2025-05-05
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Server versions 2025.1.6.0 and earlier
Description
The issue is related to improper access control in the PAM feature, allowing a PAM user to self-approve their PAM requests even if disallowed by the configured policy. This can be achieved via specific user interface actions.
Recommendations
For Devolutions Server versions 2025.1.6.0 and earlier, consider restricting access to the PAM feature until a patch is available, or apply specific configuration changes to the user interface to prevent self-approval of PAM requests.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Devolutions Server