Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature
This issue affects the following versions :
* Devolutions Server 2025.2.2.0 through 2025.2.4.0
*
Devolutions Server 2025.1.11.0 and earlier
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2025-0012/ |
|
History
Wed, 08 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* |
Wed, 23 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions devolutions Server |
|
| Vendors & Products |
Devolutions
Devolutions devolutions Server |
Tue, 22 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.4.0 * Devolutions Server 2025.1.11.0 and earlier | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-07-22T17:00:15.146Z
Updated: 2025-07-22T18:38:07.567Z
Reserved: 2025-06-26T17:34:35.373Z
Link: CVE-2025-6741
Updated: 2025-07-22T18:37:24.362Z
Status : Analyzed
Published: 2025-07-22T17:15:34.057
Modified: 2025-10-08T16:16:20.637
Link: CVE-2025-6741
No data.