Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe.
This issue affects the following versions :
Devolutions Server 2025.1.11.0 and earlier
| Software | From | Fixed in |
|---|---|---|
| devolutions / devolutions_server | - | 2025.1.11.0.x |
| devolutions / devolutions_server | 2025.2.2.0 | 2025.2.4.0 |