PT-2025-42394 · Devolutions · Devolutions Server

Published

2025-10-15

·

Updated

2025-12-03

·

CVE-2025-11619

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Server versions prior to 2025.3.3
Description A flaw exists in Devolutions Server where improper certificate validation occurs when connecting to gateways. This allows attackers in a Man-in-the-Middle (MitM) position to intercept traffic, potentially decrypting and modifying it.
Recommendations Update Devolutions Server to version 2025.3.3 or later.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-11619

Affected Products

Devolutions Server