CVE-2025-2278

MEDIUM

Devolutions Server < 2025.1.3.0 - Authenticated Improper Access Control in Temporary Access Requests

Title source: llm
STIX 2.1

Description

Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0042
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
devolutions/devolutions_server < 2025.1.3.0
Published Mar 13, 2025
Tracked Since Feb 18, 2026