Improper certificate validation in the PAM propagation WinRM connections
allows a network attacker to perform a man-in-the-middle attack via
disabled TLS certificate verification.
allows a network attacker to perform a man-in-the-middle attack via
disabled TLS certificate verification.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0005/ |
|
History
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Fri, 20 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | |
| Weaknesses | CWE-295 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-03-20T12:52:55.762Z
Reserved: 2026-03-19T18:23:32.838Z
Link: CVE-2026-4434
No data.
Status : Awaiting Analysis
Published: 2026-03-20T13:16:13.043
Modified: 2026-03-20T13:37:50.737
Link: CVE-2026-4434
No data.
OpenCVE Enrichment
Updated: 2026-03-20T16:27:17Z
Weaknesses