Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2025.2.5.0
A deadlock vulnerability has been identified in the Privileged Access Management (PAM) automatic check-in feature of Devolutions Server. This deadlock occurs in the scheduling service, allowing passwords to remain valid beyond their intended check-out period. The issue affects Devolutions Server versions through 2025.2.5.0.
Exploitation of this vulnerability can lead to passwords being improperly retained beyond their designated check-out time, potentially allowing unauthorized access.
Users are advised to upgrade to Devolutions Server version 2025.2.7.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.