Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qmwg-p2m2-4r2x

Опубликовано: 22 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.5
CVSS3: 7.7

Описание

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe.

This issue affects the following versions :

  • Devolutions Server 2025.2.2.0 through 2025.2.3.0

Devolutions Server 2025.1.11.0 and earlier

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe.

This issue affects the following versions :

  • Devolutions Server 2025.2.2.0 through 2025.2.3.0

Devolutions Server 2025.1.11.0 and earlier

EPSS

Процентиль: 34%
0.00136
Низкий

9.5 Critical

CVSS4

7.7 High

CVSS3

Дефекты

CWE-1391

Связанные уязвимости

CVSS3: 7.7
nvd
7 месяцев назад

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier

EPSS

Процентиль: 34%
0.00136
Низкий

9.5 Critical

CVSS4

7.7 High

CVSS3

Дефекты

CWE-1391