Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier
The emergency authentication component generates short, weak access codes. Due to the limited space of possible values, a network attacker is able to exhaust all combinations in real time and hit the correct code (brute force attack). The mechanism does not apply sufficient protection against multiple guessing attempts — this corresponds to the CWE-1391 category (Use of Weak Credentials). The attack requires no user interaction or prior privileges, although the vector indicates certain environmental conditions (AC:H, AT:P) required to carry it out.
A successful attack allows an attacker to completely bypass authentication and gain unauthorized access to Devolutions Server, which may lead to takeover of managed credentials and compromise of dependent systems.
Devolutions Server should be immediately updated to a version newer than 2025.2.3.0 (outside the vulnerable range) and patches indicated in the vendor's official security bulletin should be applied: https://devolutions.net/security/advisories/DEVO-2025-0012/. Until updating, disabling or limiting access to the emergency authentication component should be considered.
Devolutions Server versions 2025.2.2.0 and 2025.2.3.0, as well as Devolutions Server 2025.1.11.0 and earlier
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDevolutions Server
APPDevolutions≤ 2025.1.11.02025.2.2.0 – 2025.2.4.0 (excl.)
Related vulnerabilities
Devolutions Server: nieuprawnione usuwanie kont PAM przez bulk deletion
Authentication bypass w Devolutions Server przez sfałszowany JWT (Entra ID)
Devolutions Server — spoofing komunikatu błędu przez nieprawidłową walidację danych wejściowych
SQL Injection w module remote-sessions Devolutions Server
Devolutions Server – nieautoryzowane zatwierdzanie wniosków o dostęp tymczasowy