CVE-2025-8312: High severity Devolutions Server vulnerability
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) :
Devolutions Server 2025.2.2.0 through 2025.2.5.0 Devolutions Server 2025.1.12.0 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Devolutions Serverto a version that resolves this vulnerability.Fixed in 2025.1.12.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8312?
CVE-2025-8312 is considered a high-severity vulnerability due to the potential for a password to remain valid beyond its intended period.
How do I fix CVE-2025-8312?
To fix CVE-2025-8312, upgrade Devolutions Server to version 2025.2.5.1 or later to resolve the deadlock issue.
Which versions of Devolutions Server are affected by CVE-2025-8312?
CVE-2025-8312 affects Devolutions Server versions up to and including 2025.2.5.0.
What impact does CVE-2025-8312 have on security?
CVE-2025-8312 can lead to unauthorized access as passwords may remain valid beyond the specified checkout period.
Is there a workaround for CVE-2025-8312?
There is no known workaround for CVE-2025-8312; the recommended action is to upgrade to the latest version.