« Volver al listado

CVE-2025-8353

Estado: AnalizadaMedia (5.9)—

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-8353",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-8353",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-30T16:17:35.703576Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security@devolutions.net",
      "affectedData": [
        {
          "vendor": "Devolutions",
          "product": "Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2025.2.4.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-30T16:15:29.407",
  "references": [
    {
      "url": "https://devolutions.net/security/advisories/DEVO-2025-0013/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@devolutions.net"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@devolutions.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-446"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing."
    },
    {
      "lang": "es",
      "value": "El problema de sincronización de la interfaz de usuario en la interfaz de aprobación de solicitudes de acceso Just-in-Time (JIT) en Devolutions Server 2025.2.4.0 y versiones anteriores permite que un atacante autenticado remoto obtenga acceso no autorizado a grupos JIT eliminados a través de un estado de interfaz de usuario obsoleto durante el procesamiento de solicitudes de pago estándar."
    }
  ],
  "lastModified": "2026-06-17T10:06:48.613",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB00AE08-7260-4CFD-BD8E-CCE9FB20AD36",
              "versionEndExcluding": "2025.2.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@devolutions.net"
}