6.5

CVE-2025-4493

Improper privilege assignment in PAM JIT privilege sets in Devolutions 
Server allows a PAM user to perform PAM JIT 
requests on unauthorized groups by exploiting a user interface issue.


This issue affects the following versions : 

  *  Devolutions Server 2025.1.3.0 through 2025.1.7.0
  *  Devolutions Server 2024.3.15.0 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DevolutionsDevolutions Server Version <= 2024.3.15.0
DevolutionsDevolutions Server Version >= 2025.1.3.0 <= 2025.1.7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.