CVE-2025-12485
EUVD-2025-3805006.11.2025, 17:15
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 * Devolutions Server 2025.2.15.0 and earlierEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 < 2025.2.17.0 |
| devolutions | devolutions_server | 2025.3.2.0 ≤ 𝑥 < 2025.3.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration