CVE-2025-13683
BaseFortify
Publication date: 2025-11-28
Last updated on: 2025-12-18
Assigner: Devolutions Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| devolutions | devolutions_server | to 2025.3.10.0 (exc) |
| devolutions | remote_desktop_manager | to 2025.3.25.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the exposure of credentials in unintended requests within Devolutions Server and Remote Desktop Manager on Windows. It means that sensitive authentication information could be accidentally sent or exposed through requests that were not meant to carry such data.
How can this vulnerability impact me? :
The impact of this vulnerability could include unauthorized access to systems or data if attackers intercept the exposed credentials. This could lead to potential compromise of accounts, data breaches, or further exploitation within affected environments.