CVE-2024-12196: Medium severity devolutions server vulnerability
Published Dec 4, 2024
·Updated
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.
Affected Software
2 affected components
Devolutions Server<2024.3.7.0
Devolutions Devolutions Server<2024.3.8.0
Event History
Dec 4, 2024
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12196?
CVE-2024-12196 has a high severity rating due to the potential for unauthorized access to sensitive password history.
2
How do I fix CVE-2024-12196?
To fix CVE-2024-12196, upgrade to Devolutions Server version 2024.3.7.1 or later, where the issue is addressed.
3
Who is affected by CVE-2024-12196?
CVE-2024-12196 affects all authenticated users of Devolutions Server versions up to 2024.3.7.0.
4
What specifically does CVE-2024-12196 allow an attacker to do?
CVE-2024-12196 allows an authenticated user to view password history without having the necessary view password permission.
5
Is CVE-2024-12196 being actively exploited?
As of now, there are no public reports confirming active exploitation of CVE-2024-12196.