- Description
- Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
- Source
- security@devolutions.net
- NVD status
- Analyzed
- Products
- devolutions_server
CVSS 3.1
- Type
- Secondary
- Base score
- 4.9
- Impact score
- 3.6
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security@devolutions.net
- CWE-312
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6DB87A4B-D40B-442F-8BF5-CA935BFADB3D",
"versionEndExcluding": "2025.3.15.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]