PT-2024-18408 · Devolutions · Devolutions Server

Published

2024-03-05

·

Updated

2025-03-28

·

CVE-2024-1901

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server version 2023.3.14.0
Description The issue allows an authenticated user with specific PAM permissions to make PAM credentials unavailable during the check-in process in PAM password rotation, resulting in a denial of service.
Recommendations For Devolutions Server version 2023.3.14.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-1901

Affected Products

Devolutions Server