Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2021-0005

A vulnerability was fixed were private key were returned unencrypted by the connections/partial endpoint.

Affected Products

Devolutions Server
2021.1.17 and earlier.
2020.3.20 (LTS) and earlier.

Change Log

Initial Publication - 2021-06-30 Added CVE - 2021-07-13

Low - CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Private key returned unencrypted in connections/partial endpoint (CVE-2021-36382)

Private keys are returned by the connections/partial endpoint without being encrypted. This could lead to data exposure for installations that do not have TLS enabled.

Affected Products

CVE(s)

CVE-2021-36382

Remediation and Workarounds

Update to Devolutions Server 2021.1.18 or higher.
Update to Devolutions Server LTS 2020.3.21 or higher.

This issue is completely mitigated when Devolutions Server is configured to use TLS. The confidentiality of private keys can also be protected by setting a strong password on them.

Devolutions Logo

Helping organizations control the IT chaos by providing highly-secure password, remote connection and privileged access management solutions.

DEVOLUTIONS

Legal & privacy | infos@devolutions.net

All rights reserved © 2025 Devolutions