CVE-2024-1901: Medium severity devolutions server vulnerability
Published Mar 5, 2024
·Updated
Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.
Affected Software
2 affected components
Devolutions Server
Devolutions Devolutions Server<=2023.3.16.0
Event History
Mar 5, 2024
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-1901?
CVE-2024-1901 is classified as a denial of service vulnerability.
2
How do I fix CVE-2024-1901?
To fix CVE-2024-1901, apply the latest security updates released by Devolutions for Devolutions Server.
3
Who is affected by CVE-2024-1901?
Authenticated users with specific PAM permissions on Devolutions Server are affected by CVE-2024-1901.
4
What can an attacker do with CVE-2024-1901?
An attacker can exploit CVE-2024-1901 to make PAM credentials unavailable, resulting in a denial of service.
5
Is there a workaround for CVE-2024-1901?
As of now, the recommended approach is to update Devolutions Server to mitigate the effects of CVE-2024-1901.