Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors.
This issue affects :
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 76.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 76.00 |
VPI 公式 vpi-v1