Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4493


Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier


Published

2025-05-28T13:15:19.817

Last Modified

2025-06-25T15:48:22.483

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-266

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application devolutions devolutions_server ≤ 2024.3.15.0 Yes
Application devolutions devolutions_server ≤ 2025.1.7.0 Yes

References