PT-2025-45339 · Devolutions · Devolutions Server

Published

2025-11-06

·

Updated

2025-11-10

·

CVE-2025-12808

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.2.15.0 through 2025.3.5.0
Description A flaw in access control allows a View-only user to access sensitive, deeply nested data, specifically custom values within password lists, potentially leading to password disclosure.
Recommendations Update Devolutions Server to a version later than 2025.3.5.0. Update Devolutions Server to a version later than 2025.2.15.0.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-12808

Affected Products

Devolutions Server