CVE-2025-2003: High severity Devolutions Server vulnerability
Published Mar 5, 2025
·Updated
Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.
Affected Software
2 affected components
Devolutions Server<=2024.3.12
Devolutions Devolutions Server<2024.3.13.0
Event History
Mar 5, 2025
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2003?
CVE-2025-2003 is considered to have a high severity due to the potential for unauthorized privilege escalation.
2
How do I fix CVE-2025-2003?
To mitigate CVE-2025-2003, upgrade to Devolutions Server version 2024.3.13 or later.
3
Who is affected by CVE-2025-2003?
CVE-2025-2003 affects users of Devolutions Server versions 2024.3.12 and earlier.
4
What type of vulnerability is CVE-2025-2003?
CVE-2025-2003 is a vulnerability related to incorrect authorization in PAM vaults.
5
Can an unauthenticated user exploit CVE-2025-2003?
No, CVE-2025-2003 requires an authenticated user to exploit the authorization flaw.