CVE-2024-6512

MEDIUM

Dovolations Server <2024.2.10 - Auth Bypass

Title source: llm
STIX 2.1

Description

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0029
EPSS Percentile 20.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
devolutions/devolutions_server < 2024.3.0
Published Sep 25, 2024
Tracked Since Feb 18, 2026