CVE-2025-11619
🟡 Monitoruj
Nieprawidłowa walidacja certyfikatów w Devolutions Server umożliwia atakującym przechwycenie ruchu.
CVSS
8.8
EPSS
0.2%
Exploit
none
Vendor
devolutions
Opis źródłowy (NVD)
Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-15 20:15:34 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 11:10:00 UTC |
Referencje
- https://devolutions.net/security/advisories/DEVO-2025-0014/ ([email protected]) [Vendor Advisory]