PT-2021-21262 · Devolutions · Devolutions Server

Published

2021-07-12

·

Updated

2022-07-12

·

CVE-2021-36382

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions prior to 2021.1.18 Devolutions Server LTS versions prior to 2020.3.20
Description The issue allows attackers to intercept private keys via a man-in-the-middle attack against the "connections/partial" endpoint, which accepts cleartext.
Recommendations For Devolutions Server versions prior to 2021.1.18, update to version 2021.1.18 or later. For Devolutions Server LTS versions prior to 2020.3.20, update to version 2020.3.20 or later. As a temporary workaround, consider restricting access to the "connections/partial" endpoint until a patch is applied.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36382

Affected Products

Devolutions Server