PT-2024-22811 · Devolutions · Devolutions Server

Published

2024-03-26

·

Updated

2025-03-28

·

CVE-2024-2921

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2024.1.6 and earlier
Description The issue is related to improper access control in PAM vault permissions, allowing an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
Recommendations For Devolutions Server versions 2024.1.6 and earlier, consider restricting access to the PAM vault permissions to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and adjust the permissions settings to ensure that only authorized users have access to sensitive PAM entries. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2921

Affected Products

Devolutions Server