CVE-2025-6523

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier
Configurations

No configuration.

History

25 Jul 2025, 15:29

Type Values Removed Values Added
Summary
  • (es) El uso de credenciales débiles en el componente de autenticación de emergencia de Devolutions Server permite a un atacante no autenticado eludir la autenticación mediante fuerza bruta los códigos de emergencia cortos generados por el servidor dentro de un plazo razonable. Este problema afecta a las siguientes versiones: * Devolutions Server 2025.2.2.0 a 2025.2.3.0 * Devolutions Server 2025.1.11.0 y anteriores

22 Jul 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7

22 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-22 17:15

Updated : 2025-07-25 15:29


NVD link : CVE-2025-6523

Mitre link : CVE-2025-6523

CVE.ORG link : CVE-2025-6523


JSON object : View

Products Affected

No product.

CWE
CWE-1391

Use of Weak Credentials