CVE-2025-3517: Medium severity devolutions server vulnerability
Published May 1, 2025
·Updated
Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.
Affected Software
2 affected components
Devolutions Server<=2025.1.5.0
Devolutions Devolutions Server<2025.1.6.0
Event History
May 1, 2025
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3517?
CVE-2025-3517 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-3517?
To fix CVE-2025-3517, update to Devolutions Server version 2025.1.5.1 or later.
3
What systems are affected by CVE-2025-3517?
CVE-2025-3517 affects Devolutions Server version 2025.1.5.0 and earlier.
4
What type of vulnerability is CVE-2025-3517?
CVE-2025-3517 is a privilege escalation vulnerability related to the PAM JIT feature.
5
What actions can exploit CVE-2025-3517?
CVE-2025-3517 can be exploited through specific actions such as editing the username of a PAM JIT account.