CRITICAL🇵🇱 Wersja polska

CVE-2025-6523

CVSS 9.5v4.0pub. 2025-07-22upd. 2025-11-25

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier

🤖 AI Analysis
How it works

The emergency authentication component generates short, weak access codes. Due to the limited space of possible values, a network attacker is able to exhaust all combinations in real time and hit the correct code (brute force attack). The mechanism does not apply sufficient protection against multiple guessing attempts — this corresponds to the CWE-1391 category (Use of Weak Credentials). The attack requires no user interaction or prior privileges, although the vector indicates certain environmental conditions (AC:H, AT:P) required to carry it out.

Impact

A successful attack allows an attacker to completely bypass authentication and gain unauthorized access to Devolutions Server, which may lead to takeover of managed credentials and compromise of dependent systems.

Mitigation & patch

Devolutions Server should be immediately updated to a version newer than 2025.2.3.0 (outside the vulnerable range) and patches indicated in the vendor's official security bulletin should be applied: https://devolutions.net/security/advisories/DEVO-2025-0012/. Until updating, disabling or limiting access to the emergency authentication component should be considered.

Who is affected

Devolutions Server versions 2025.2.2.0 and 2025.2.3.0, as well as Devolutions Server 2025.1.11.0 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Devolutions Server

    APP
    Devolutions
    ≤ 2025.1.11.02025.2.2.0 – 2025.2.4.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-3130CRITICAL9.8PL ✓same product

Devolutions Server: nieuprawnione usuwanie kont PAM przez bulk deletion

CVE-2026-3224CRITICAL9.8PL ✓same product

Authentication bypass w Devolutions Server przez sfałszowany JWT (Entra ID)

CVE-2026-3204CRITICAL9.8PL ✓same product

Devolutions Server — spoofing komunikatu błędu przez nieprawidłową walidację danych wejściowych

CVE-2026-0610CRITICAL9.8PL ✓same product

SQL Injection w module remote-sessions Devolutions Server

CVE-2025-11957CRITICAL9.0PL ✓same product

Devolutions Server – nieautoryzowane zatwierdzanie wniosków o dostęp tymczasowy