PT-2025-30445 · Devolutions · Devolutions Server

Gino Boudreau

·

Published

2025-07-22

·

Updated

2025-11-25

·

CVE-2025-6741

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.1.11.0 and earlier Devolutions Server versions 2025.2.2.0 through 2025.2.4.0
Description Improper access control in the secure message component of Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature.
Recommendations Update Devolutions Server to a version later than 2025.1.11.0. Update Devolutions Server to a version later than 2025.2.4.0.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-6741

Affected Products

Devolutions Server