CVE-2024-4846

MEDIUM

Devolutions Server < 2024.1.15.0 - Authenticated Authentication Bypass via 2FA Spoofing

Title source: llm
STIX 2.1

Description

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.

References (1)

Core 1

Scores

CVSS v3 6.3
EPSS 0.0039
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (1)
devolutions/devolutions_server < 2024.1.15.0
Published Jun 25, 2024
Tracked Since Feb 18, 2026