Devolutions Hub Reporting Service Improper Certificate Validation Vulnerability Allowing Man-in-the-Middle Attacks
Vulnerability
A vulnerability exists in Devolutions Hub Reporting Service versions through 2025.3.1.1 that allows network attackers to conduct man-in-the-middle attacks. This is due to improper certificate validation, as TLS certificate verification is disabled, enabling interception and manipulation of communications.
Impact
Exploitation of this vulnerability could lead to a man-in-the-middle attack, allowing an attacker to intercept and potentially alter communications between the client and the server.
Remediation
Users are advised to upgrade to Devolutions Hub Reporting Service version 2026.1.1.0 or higher.
Added: Mar 18, 2026, 8:25 PM
Updated: Mar 18, 2026, 8:25 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
3.1exploitability
6.2remediation
0.0relevance
4.1threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
