CVE-2024-2921: Critical severity devolutions server vulnerability
Published Mar 26, 2024
·Updated
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
Affected Software
2 affected components
Devolutions Devolutions Server<2024.1.10.0
Devolutions Devolutions Server<2024.1.8.0
Event History
Mar 26, 2024
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-2921?
CVE-2024-2921 has been rated as a medium severity vulnerability due to improper access control in PAM vault permissions.
2
How do I fix CVE-2024-2921?
To fix CVE-2024-2921, upgrade to Devolutions Server version 2024.1.11.0 or later.
3
Who is affected by CVE-2024-2921?
CVE-2024-2921 affects all versions of Devolutions Server up to and including 2024.1.10.0.
4
What type of vulnerability is CVE-2024-2921?
CVE-2024-2921 is classified as an access control vulnerability.
5
Can CVE-2024-2921 be exploited by authenticated users?
Yes, CVE-2024-2921 can be exploited by authenticated users who have access to the PAM.