Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version
affected
2025.2.2.0 (custom)
affected
Description
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.4.0 * Devolutions Server 2025.1.11.0 and earlier
Problem types
CWE-284: Improper Access Control
Product status
Any version
2025.2.2.0 (custom)
Credits
Gino Boudreau (mononclemich)
References
devolutions.net/security/advisories/DEVO-2025-0012/