Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2025-0011/ |
![]() ![]() |
History
Wed, 02 Jul 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Devolutions
Devolutions devolutions Server |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Devolutions
Devolutions devolutions Server |
Thu, 05 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 05 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 05 Jun 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable. | |
Weaknesses | CWE-284 | |
References |
|

Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-06-05T13:36:41.991Z
Updated: 2025-06-05T14:09:18.593Z
Reserved: 2025-04-17T15:07:14.619Z
Link: CVE-2025-3768

Updated: 2025-06-05T14:09:10.418Z

Status : Analyzed
Published: 2025-06-05T14:15:32.103
Modified: 2025-07-02T13:06:47.297
Link: CVE-2025-3768

No data.