CVE-2025-2277: Infoleak
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2277?
CVE-2025-2277 is considered a high-severity vulnerability due to the potential exposure of sensitive SSH passwords.
How do I fix CVE-2025-2277?
To fix CVE-2025-2277, upgrade Devolutions Server to version 2024.3.14 or later, where the password masking issue is resolved.
What causes CVE-2025-2277?
CVE-2025-2277 is caused by the lack of password masking in the web-based SSH authentication component of affected Devolutions Server versions.
Who is affected by CVE-2025-2277?
Users of Devolutions Server versions 2024.3.13 and earlier are affected by CVE-2025-2277.
What should I do if I can't upgrade immediately to fix CVE-2025-2277?
If immediate upgrade is not possible, avoid using the SSH authentication feature until the vulnerability is addressed.