CVE-2025-3768

MEDIUM

Dovolations Server <2025.1.10.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.

References (1)

Core 1

Scores

CVSS v3 5.0
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
devolutions/devolutions_server < 2025.1.10.0
Published Jun 05, 2025
Tracked Since Feb 18, 2026