4.9
CVE-2026-3221
- EPSS 0.02%
- Veröffentlicht 25.02.2026 18:29:11
- Zuletzt bearbeitet 28.02.2026 00:43:23
- Quelle security@devolutions.net
- CVE-Watchlists
- Unerledigt
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devolutions ≫ Devolutions Server Version < 2025.3.15.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.037 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.