CVE-2024-4846

MEDIUM

Devolutions Server < 2024.1.15.0 - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.

Scores

CVSS v3 6.3
EPSS 0.0008
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (1)
devolutions/devolutions_server < 2024.1.15.0
Published Jun 25, 2024
Tracked Since Feb 18, 2026