PT-2025-30445 · Devolutions · Devolutions Server

·

CVE-2025-6741

·

Published

2025-07-22

·

Updated

2025-11-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.1.11.0 and earlier Devolutions Server versions 2025.2.2.0 through 2025.2.4.0
Description Improper access control in the secure message component of Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature.
Recommendations Update Devolutions Server to a version later than 2025.1.11.0. Update Devolutions Server to a version later than 2025.2.4.0.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6741

Affected Products

Devolutions Server