Vulnerabilities > Teradici

DATE CVE VULNERABILITY TITLE RISK
2020-08-11 CVE-2020-13175 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Teradici products
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially crafted HTTP request.
network
low complexity
teradici CWE-829
7.5
2020-08-11 CVE-2020-13174 Improper Restriction of Rendered UI Layers or Frames vulnerability in Teradici Pcoip Management Console 20.01.1/20.04
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
network
low complexity
teradici CWE-1021
6.1
2020-05-28 CVE-2020-13173 Race Condition vulnerability in Teradici Pcoip Graphics Agent and Pcoip Standard Agent
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing an application which acquires that named pipe.
local
low complexity
teradici CWE-362
7.8
2020-03-25 CVE-2020-10965 Missing Authentication for Critical Function vulnerability in Teradici Pcoip Management Console 19.11.1/20.01.0
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account.
network
high complexity
teradici CWE-306
8.1
2020-01-08 CVE-2019-20362 Unquoted Search Path or Element vulnerability in Teradici products
In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file.
local
low complexity
teradici CWE-428
7.8