CVE-2025-2277
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 13, 2025
Updated: Mar 28, 2025
CWE ID 502
Summary
CVE-2025-2277 is a vulnerability affecting Devolutions Server 2024.3.13 and earlier versions. This issue exposes passwords in web-based SSH authentication, allowing users to inadvertently leak their SSH passwords due to missing password masking. An attacker who gains access to the affected system could potentially obtain sensitive password information. Users are urged to update their Devolutions Server to a patch release as soon as possible to mitigate this risk. Failure to do so could result in unauthorized access to the system and its resources.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.