CVE-2025-4316: Medium severity devolutions server vulnerability
Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions.
This issue affects Devolutions Server versions from 2025.1.3.0 through 2025.1.6.0, and all versions up to 2024.3.15.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4316?
CVE-2025-4316 has been classified as a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2025-4316?
To fix CVE-2025-4316, upgrade to Devolutions Server version 2025.1.6.1 or later where the issue is resolved.
What systems are affected by CVE-2025-4316?
CVE-2025-4316 affects Devolutions Server version 2025.1.6.0 and earlier.
What is the impact of CVE-2025-4316?
The impact of CVE-2025-4316 allows PAM users to self-approve requests contrary to set policy, potentially leading to unauthorized privilege escalations.
Who is vulnerable to CVE-2025-4316?
Organizations using Devolutions Server version 2025.1.6.0 or earlier with PAM feature enabled are vulnerable to CVE-2025-4316.