PT-2025-30444 · Devolutions · Devolutions Server

Gino Boudreau

·

Published

2025-07-22

·

Updated

2025-11-25

·

CVE-2025-6523

CVSS v4.0

9.5

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.1.11.0 through 2025.2.3.0
Description The use of weak credentials in the emergency authentication component allows an unauthenticated attacker to bypass authentication by brute-forcing the short emergency codes generated by the server.
Recommendations Devolutions Server versions prior to 2025.2.3.0 should be updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-6523

Affected Products

Devolutions Server