CVE-2025-6523

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-22 17:15

Updated : 2025-11-25 18:15


NVD link : CVE-2025-6523

Mitre link : CVE-2025-6523

CVE.ORG link : CVE-2025-6523


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-1391

Use of Weak Credentials