CVE-2025-5382: Medium severity devolutions server vulnerability
Published Jun 5, 2025
·Updated
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.
Affected Software
2 affected components
Devolutions Server<=2025.1.7.0
Devolutions Devolutions Server<2025.1.9.0
Event History
Jun 5, 2025
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5382?
CVE-2025-5382 is considered a high severity vulnerability due to improper access control in the user's MFA feature.
2
How do I fix CVE-2025-5382?
To fix CVE-2025-5382, update Devolutions Server to version 2025.1.8.0 or later.
3
What types of users are affected by CVE-2025-5382?
Users with user management permission can exploit CVE-2025-5382 to change or remove administrators' MFA.
4
What is the impact of CVE-2025-5382 on Devolutions Server?
The impact of CVE-2025-5382 allows unauthorized users to alter security settings, compromising account security.
5
Is CVE-2025-5382 present in earlier versions of Devolutions Server?
Yes, CVE-2025-5382 affects Devolutions Server versions up to and including 2025.1.7.0.