PT-2025-19709 · Devolutions · Devolutions Server

Published

2025-05-05

·

Updated

2025-05-05

·

CVE-2025-4316

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.1.6.0 and earlier
Description The issue is related to improper access control in the PAM feature, allowing a PAM user to self-approve their PAM requests even if disallowed by the configured policy. This can be achieved via specific user interface actions.
Recommendations For Devolutions Server versions 2025.1.6.0 and earlier, consider restricting access to the PAM feature until a patch is available, or apply specific configuration changes to the user interface to prevent self-approval of PAM requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-15267
CVE-2025-4316

Affected Products

Devolutions Server