PT-2021-21262 · Devolutions · Devolutions Server
Published
2021-07-12
·
Updated
2022-07-12
·
CVE-2021-36382
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Server versions prior to 2021.1.18
Devolutions Server LTS versions prior to 2020.3.20
Description
The issue allows attackers to intercept private keys via a man-in-the-middle attack against the "connections/partial" endpoint, which accepts cleartext.
Recommendations
For Devolutions Server versions prior to 2021.1.18, update to version 2021.1.18 or later.
For Devolutions Server LTS versions prior to 2020.3.20, update to version 2020.3.20 or later.
As a temporary workaround, consider restricting access to the "connections/partial" endpoint until a patch is applied.
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Devolutions Server