CVE-2025-6523
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : Devolutions Server 2025.2.2.0 through 2025.2.3.0 Devolutions Server 2025.1.11.0 and earlier.
HIGH · CVSS 7.7
EPSS 0.00182
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0