CVE-2025-6523

7.7

Devolutions · Devolutions Server

An authentication bypass vulnerability in Devolutions Server allows unauthenticated attackers to perform brute force attacks against weak emergency authentication codes.

Executive summary

A critical authentication vulnerability in Devolutions Server allows unauthenticated attackers to bypass security controls through brute force, posing a significant risk of unauthorized system access.

Vulnerability

This flaw involves the use of weak credentials within the emergency authentication component, enabling an unauthenticated attacker to bypass login requirements by brute forcing short emergency codes within a feasible timeframe.

Business impact

The ability for an unauthenticated user to bypass authentication mechanisms directly compromises the confidentiality, integrity, and availability of the Devolutions Server environment. With a CVSS score of 7.7, this represents a High severity risk that could lead to full administrative account takeover, unauthorized data exfiltration, and potential lateral movement within the network.

Remediation

Immediate Action: Monitor the official Devolutions security advisory page for the release of a security patch and apply the update to all affected instances immediately upon availability.

Proactive Monitoring: Review authentication logs for suspicious patterns, such as multiple failed login attempts or unusual activity originating from the emergency authentication endpoint.

Compensating Controls: Implement strict network access controls to limit exposure of the management interface and utilize a Web Application Firewall to detect and block automated brute force attempts targeting authentication endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete authentication bypass, this vulnerability must be treated as a high priority. Administrators should restrict access to the emergency authentication interface until a vendor-supplied patch is successfully deployed to remediate the weakness in credential generation.

More Devolutions CVEs

Sources

Originally found and disclosed by Gino Boudreau (mononclemich), per the CVE Program record.