CVE-2025-2277

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 13, 2025
Updated: Mar 28, 2025
CWE ID 502

Summary

CVE-2025-2277 is a vulnerability affecting Devolutions Server 2024.3.13 and earlier versions. This issue exposes passwords in web-based SSH authentication, allowing users to inadvertently leak their SSH passwords due to missing password masking. An attacker who gains access to the affected system could potentially obtain sensitive password information. Users are urged to update their Devolutions Server to a patch release as soon as possible to mitigate this risk. Failure to do so could result in unauthorized access to the system and its resources.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share