CVE-2023-5575: Medium severity devolutions server vulnerability
Published Oct 16, 2023
·Updated
Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.
Affected Software
1 affected component
Devolutions Devolutions Server<=2022.3.13.0
Event History
Oct 16, 2023
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5575.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier'.
3
What is the severity of CVE-2023-5575?
The severity of CVE-2023-5575 is medium (6.5).
4
How does CVE-2023-5575 affect Devolutions Server?
CVE-2023-5575 affects Devolutions Server 2022.3.13.0 and earlier.
5
How can an attacker exploit CVE-2023-5575?
An attacker that compromised a low privileged user can exploit CVE-2023-5575 by accessing entries via a specific combination of permissions in the entry and in its parent.