Vulnerability record · CVE-2021-36382 · published 12 July 2021
CVE-2021-36382: Devolutions server cleartext transmission vulnerability
Devolutions · Devolutions Server
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
Description
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2021-0005 | Vendor Advisory |
| https://devolutions.net/security/advisories/DEVO-2021-0005 | Vendor Advisory |
Track CVE-2021-36382 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36382), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.