Cyber Posture

CVE-2025-2277

High

Published: 13 March 2025

Published
13 March 2025
Modified
28 March 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0030 53.7th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-2277 is a high-severity Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability in Devolutions Devolutions Server. Its CVSS base score is 7.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 46.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 IA-6 (Authentication Feedback) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 2 other techniques. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly requires obscuring feedback of authentication information, such as masking SSH passwords during web-based input to prevent visual exposure to unauthorized viewers.

prevent

Mandates protection of authenticators like SSH passwords commensurate with their sensitivity, addressing disclosure risks in authentication components.

prevent

Requires timely identification, reporting, and correction of flaws like missing password masking, directly mitigating the vulnerability through remediation.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1021.004 SSH Lateral Movement
Adversaries may use [Valid Accounts](https://attack.
Why these techniques?

Vulnerability in public-facing web SSH auth component enables unauthenticated exploitation for credential exposure (T1190, T1552) and subsequent SSH access (T1021.004).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

NVD Description

Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.

Deeper analysisAI

CVE-2025-2277 affects the web-based SSH authentication component in Devolutions Server versions 2024.3.13 and earlier. The vulnerability stems from missing password masking, leading to the exposure of sensitive SSH passwords. It is associated with CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-522 (Insufficiently Protected Credentials), earning a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), driven by high confidentiality impact.

Unauthenticated attackers with network access can exploit this issue with low attack complexity and no user interaction required. Exploitation allows remote adversaries to obtain exposed SSH passwords, potentially enabling unauthorized access to SSH services or further lateral movement within affected environments.

The Devolutions security advisory DEVO-2025-0004, available at https://devolutions.net/security/advisories/DEVO-2025-0004/, provides guidance on mitigation and patching for this vulnerability.

Details

CWE(s)

Affected Products

devolutions
devolutions server
≤ 2025.1.3.0

CVEs Like This One

CVE-2026-0610Same product: Devolutions Devolutions Server
CVE-2026-1007Same product: Devolutions Devolutions Server
CVE-2026-4828Same product: Devolutions Devolutions Server
CVE-2026-3204Same product: Devolutions Devolutions Server
CVE-2026-4924Same product: Devolutions Devolutions Server
CVE-2025-2280Same product: Devolutions Devolutions Server
CVE-2026-3224Same product: Devolutions Devolutions Server
CVE-2026-4434Same product: Devolutions Devolutions Server
CVE-2025-2003Same product: Devolutions Devolutions Server
CVE-2026-3130Same product: Devolutions Devolutions Server

References