Back to Database
Status published
Unknown
CVE-2025-5382
Improper access control in users MFA feature in Devolutions Server...
Vulnerability Description
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5382
Credits & Attribution
No credits recorded in the NVD database.
More from Devolutions
View All →CVE-2025-8353
UI synchronization issue in the Just-in-Time (JIT) access request approval...
Unknown
0
CVE-2025-8312
Deadlock in PAM automatic check-in feature in Devolutions Server allows...
Unknown
0
CVE-2025-6741
Improper access control in secure message component in Devolutions Server...
High
7.1
CVE-2025-6523
Use of weak credentials in emergency authentication component in Devolutions...
Critical
9.5
CVE-2025-5334
Exposure of private personal information to an unauthorized actor in...
Unknown
0
Affected Vendor
Devolutions
View all reports →Affected Software
Server
Vulnerable Versions:
0
Timeline
Official Publish:
June 5th, 2025
Last Modified:
June 5th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available