Lucene search

K
nvd[email protected]NVD:CVE-2020-13179
HistoryAug 11, 2020 - 7:15 p.m.

CVE-2020-13179

2020-08-1119:15:17
CWE-200
CWE-212
web.nvd.nist.gov
1
teradici pcoip
broker protocol
memory dump

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

12.6%

Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single sign-on procedure.

Affected configurations

Nvd
Node
teradicigraphics_agentRange<20.04.1windows
OR
teradicipcoip_standard_agentRange<20.04.1windows
VendorProductVersionCPE
teradicigraphics_agent*cpe:2.3:a:teradici:graphics_agent:*:*:*:*:*:windows:*:*
teradicipcoip_standard_agent*cpe:2.3:a:teradici:pcoip_standard_agent:*:*:*:*:*:windows:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2020-13179