Man-in-the-Middle Vulnerability in Devolutions Server
CVE-2021-36382

2.6LOW

Key Information:

Vendor
CVE Published:
12 July 2021

What is CVE-2021-36382?

Devolutions Server, in versions prior to 2021.1.18 and LTS versions before 2020.3.20, is susceptible to a man-in-the-middle attack. Attackers can exploit this vulnerability to intercept private keys through unencrypted connections, posing a significant risk to the confidentiality of sensitive information. It is crucial for users to upgrade to the latest versions to safeguard against potential attacks. More details can be found in the security advisory issued by Devolutions.

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.