allows a network attacker to perform a man-in-the-middle attack via
disabled TLS certificate verification.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0005/ |
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Man‑in‑the‑Middle via Disabled TLS Certificate Verification in Devolutions Server PAM WinRM Connections |
Mon, 30 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions devolutions Server
|
|
| CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devolutions devolutions Server
|
Wed, 25 Mar 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Man‑in‑the‑Middle via Disabled TLS Certificate Verification in Devolutions Server PAM WinRM Connections |
Mon, 23 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Fri, 20 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | |
| Weaknesses | CWE-295 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-03-23T14:12:02.673Z
Reserved: 2026-03-19T18:23:32.838Z
Link: CVE-2026-4434
Updated: 2026-03-23T14:10:54.645Z
Status : Analyzed
Published: 2026-03-20T13:16:13.043
Modified: 2026-03-30T15:23:51.527
Link: CVE-2026-4434
No data.
OpenCVE Enrichment
Updated: 2026-03-30T20:58:17Z