Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2025-0011/ |
|
History
Wed, 02 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions devolutions Server |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devolutions
Devolutions devolutions Server |
Thu, 05 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 05 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable. | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-06-05T13:36:41.991Z
Updated: 2025-06-05T14:09:18.593Z
Reserved: 2025-04-17T15:07:14.619Z
Link: CVE-2025-3768
Updated: 2025-06-05T14:09:10.418Z
Status : Analyzed
Published: 2025-06-05T14:15:32.103
Modified: 2025-07-02T13:06:47.297
Link: CVE-2025-3768
No data.