VYPR
Unrated severityNVD Advisory· Published Oct 13, 2023· Updated Sep 17, 2024

CVE-2023-5240

CVE-2023-5240

Description

Improper access control in Devolutions Server PAM propagation scripts allows users with permission to manage scripts to retrieve stored passwords via a GET request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Devolutions Server PAM propagation scripts allows users with permission to manage scripts to retrieve stored passwords via a GET request.

Vulnerability

An improper access control vulnerability exists in the PAM propagation scripts feature of Devolutions Server version 2023.2.8.0 and earlier [1]. The flaw allows an authenticated user who has permission to manage PAM propagation scripts to retrieve passwords stored within those scripts by sending a GET request, bypassing the intended access controls that should prevent such retrieval [1].

Exploitation

To exploit this vulnerability, an attacker must have a valid user account on the Devolutions Server with the specific permission to manage PAM propagation scripts [1]. No further privileges are required. The attacker can then craft a GET request to the relevant endpoint to retrieve the passwords stored in the scripts [1].

Impact

Successful exploitation results in the disclosure of passwords stored within PAM propagation scripts. This can lead to unauthorized access to systems or services that those passwords protect, potentially compromising confidentiality and integrity [1]. The scope of impact depends on the resources secured by the exposed passwords [1].

Mitigation

Devolutions has released version 2023.2.9.0 to address this vulnerability [1]. Users should upgrade to this version or later. As a workaround, administrators may consider restricting the permission to manage PAM propagation scripts to only highly trusted accounts until the upgrade is applied [1].

References
  1. advisories

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Go Vela/Serverllm-fuzzy
    Range: <=2023.2.8.0
  • Devolutions/Serverv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.