Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2025.3.5.0
A vulnerability exists in Devolutions Server in versions through 2025.3.5.0, where improper privilege management during pre-MFA cookie handling allows low-privileged authenticated users to impersonate other accounts by replaying pre-MFA cookies. However, this does not bypass the MFA verification step for the target account.
Exploitation of this vulnerability allows for account impersonation, where a low-privileged user can act as another user, although the target's MFA verification is still required.
Users are advised to upgrade to Devolutions Server version 2025.3.6.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.