Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackersĀ in MitM position to intercept traffic.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Devolutions_server | Devolutions | * | 2025.2.15.0 (excluding) |
| Devolutions_server | Devolutions | 2025.3 (including) | 2025.3.3.0 (excluding) |