PT-2025-45338 · Devolutions · Devolutions Server

Published

2025-11-06

·

Updated

2025-11-13

·

CVE-2025-12485

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.2.15.0 through 2025.3.5.0
Description A flaw exists in Devolutions Server related to improper privilege management during the handling of pre-MFA cookies. A low-privileged authenticated user can potentially impersonate another account by replaying the pre-MFA cookie. This issue does not circumvent the target account’s multi-factor authentication verification process.
Recommendations Devolutions Server versions prior to 2025.3.5.0 should be updated. Devolutions Server version 2025.3.5.0 should be updated.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-12485

Affected Products

Devolutions Server