Описание
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2026.2.4.0 (включая) до 2026.2.9.0 (исключая)
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00216
Низкий
2.7 Low
CVSS3
Дефекты
CWE-1284
Связанные уязвимости
CVSS3: 2.7
github
2 месяца назад
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
EPSS
Процентиль: 12%
0.00216
Низкий
2.7 Low
CVSS3
Дефекты
CWE-1284