CVE-2025-6523
22.07.2025, 17:15
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlierEnginsight
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 ≤ 2025.1.11.0 |
| devolutions | devolutions_server | 2025.2.2.0 ≤ 𝑥 < 2025.2.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration