Vulnerabilidades em Devolutions

176 resultados
Análise Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2025-4493MEDIUMImproper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorizeEPSS 0.4%CVE-2025-13765MEDIUMExposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: beEPSS 0.4%CVE-2023-2118MEDIUMInsufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send suEPSS 0.4%CVE-2024-1764HIGHImproper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continueEPSS 0.4%CVE-2025-4316MEDIUMImproper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the EPSS 0.4%CVE-2025-1231MEDIUMImproper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user paEPSS 0.4%CVE-2026-3563MEDIUMImproper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with EPSS 0.3%CVE-2024-1901MEDIUMDenial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with sEPSS 0.3%CVE-2026-4924HIGHImproper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attackeEPSS 0.3%CVE-2026-4064HIGHMissing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with anEPSS 0.3%CVE-2025-0691MEDIUMImproper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "EEPSS 0.3%CVE-2025-8312HIGHDeadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out EPSS 0.3%CVE-2026-9047HIGHImproper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knEPSS 0.3%CVE-2023-6288Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES eEPSS 0.3%CVE-2025-3517MEDIUMIncorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a prevEPSS 0.3%CVE-2025-11957CRITICALImproper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to EPSS 0.3%CVE-2026-0610CRITICALSQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12EPSS 0.3%CVE-2026-16800HIGHImproper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier aEPSS 0.3%CVE-2026-3131MEDIUMImproper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user witEPSS 0.3%CVE-2026-12105MEDIUMImproper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplicationEPSS 0.3%