CVE-2022-33996: High severity devolutions server vulnerability
Published Jul 7, 2022
·Updated
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
Affected Software
1 affected component
Devolutions Devolutions Server<2022.2.0
Event History
Jul 7, 2022
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
Description
Frequently Asked Questions
1
What is CVE-2022-33996?
CVE-2022-33996 is a vulnerability in Devolutions Server before 2022.2 that allows a new user with a preexisting username to inherit the permissions of the previous user.
2
How does CVE-2022-33996 affect Devolutions Server?
CVE-2022-33996 affects Devolutions Server before 2022.2.
3
What is the severity of CVE-2022-33996?
CVE-2022-33996 has a severity rating of 8.8 (high).
4
What is the CWE of CVE-2022-33996?
CVE-2022-33996 is associated with CWE-276 (Incorrect Default Permissions).
5
How can I protect my Devolutions Server from CVE-2022-33996?
To protect your Devolutions Server from CVE-2022-33996, you should update to version 2022.2 or higher.