CVE-2025-6523

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier
CVSS

No CVSS.

Configurations

No configuration.

History

22 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-22 17:15

Updated : 2025-07-22 19:15


NVD link : CVE-2025-6523

Mitre link : CVE-2025-6523


JSON object : View

Products Affected

No product.

CWE

No CWE.