ZeroHour

CVE-2023-5240

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description

Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

Vendors
devolutions
Products
devolutions server
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.