CVE-2025-11619: High severity Devolutions Server vulnerability
Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11619?
CVE-2025-11619 has a high severity rating due to its potential for Man-in-the-Middle (MitM) attacks.
How do I fix CVE-2025-11619?
To fix CVE-2025-11619, upgrade to Devolutions Server version 2025.3.3 or later, which addresses the improper certificate validation issue.
What are the risks associated with CVE-2025-11619?
CVE-2025-11619 allows attackers to intercept and manipulate traffic, compromising the confidentiality and integrity of sensitive data.
Which versions of Devolutions Server are affected by CVE-2025-11619?
CVE-2025-11619 affects Devolutions Server versions up to and including 2025.3.2.
What exploit scenarios are possible with CVE-2025-11619?
Exploit scenarios for CVE-2025-11619 involve attackers intercepting traffic between clients and gateways, potentially leading to data breaches.