6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Improper access control in Devolutions Server 2025.3.5.0 and earlier allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.
Basic Information
ID
CVE-2025-12808
Source
DEVOLUTIONS
Published
Nov 6, 2025 at 16:36
Modified
Nov 6, 2025 at 19:39
Affected Product
Vendor
Devolutions
Product
Server
Affected Versions
Devolutions Server 0