Lucene search

K
cveTeradiciCVE-2020-13179
HistoryAug 11, 2020 - 7:15 p.m.

CVE-2020-13179

2020-08-1119:15:17
CWE-200
CWE-212
Teradici
web.nvd.nist.gov
26
teradici
pcoip
windows
cve-2020-13179
vulnerability
security
memory dump
single sign-on

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0

Percentile

12.6%

Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single sign-on procedure.

Affected configurations

Nvd
Node
teradicigraphics_agentRange<20.04.1windows
OR
teradicipcoip_standard_agentRange<20.04.1windows
VendorProductVersionCPE
teradicigraphics_agent*cpe:2.3:a:teradici:graphics_agent:*:*:*:*:*:windows:*:*
teradicipcoip_standard_agent*cpe:2.3:a:teradici:pcoip_standard_agent:*:*:*:*:*:windows:*:*

CNA Affected

[
  {
    "product": "- PCoIP Standard Agent for Windows - PCoIP Graphics Agent for Windows",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "PCoIP Standard Agent for Windows 20.04 and earlier, PCoIP Graphics Agent for Windows 20.04 and earlier"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2020-13179