CVE-2023-5575
- EPSS 0.63%
- Veröffentlicht 16.10.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:42:02
Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent...
CVE-2023-5240
- EPSS 0.63%
- Veröffentlicht 13.10.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:21
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
CVE-2023-2400
- EPSS 0.44%
- Veröffentlicht 20.06.2023 17:15:09
- Zuletzt bearbeitet 09.12.2024 19:15:11
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access.
CVE-2023-2445
- EPSS 0.98%
- Veröffentlicht 02.05.2023 14:15:09
- Zuletzt bearbeitet 30.01.2025 17:15:16
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.
CVE-2023-2118
- EPSS 0.37%
- Veröffentlicht 21.04.2023 22:15:07
- Zuletzt bearbeitet 04.02.2025 20:15:46
Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.
CVE-2023-1603
- EPSS 0.62%
- Veröffentlicht 02.04.2023 21:15:08
- Zuletzt bearbeitet 25.02.2025 18:15:26
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
CVE-2023-1201
- EPSS 0.81%
- Veröffentlicht 10.03.2023 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:38:39
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
CVE-2023-0952
- EPSS 0.66%
- Veröffentlicht 01.03.2023 08:15:11
- Zuletzt bearbeitet 17.03.2025 19:15:15
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
CVE-2023-0951
- EPSS 1%
- Veröffentlicht 01.03.2023 08:15:11
- Zuletzt bearbeitet 17.03.2025 19:15:15
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privileged actions.
CVE-2023-0953
- EPSS 1.03%
- Veröffentlicht 01.03.2023 08:15:11
- Zuletzt bearbeitet 12.03.2025 14:15:14
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.