Vulnerabilities > Teradici > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-08-11 CVE-2020-13177 Uncontrolled Search Path Element vulnerability in Teradici Graphics Agent and Pcoip Standard Agent
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.
4.4
2020-08-11 CVE-2020-13176 Cross-site Scripting vulnerability in Teradici products
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16 and earlier for the Cloud Access Connector) contains a stored cross-site scripting (XSS) vulnerability which allows a remote unauthenticated attacker to poison log files with malicious JavaScript via the login page which is executed when an administrator views the logs within the application.
network
teradici CWE-79
4.3
2020-08-11 CVE-2020-13175 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Teradici products
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially crafted HTTP request.
network
low complexity
teradici CWE-829
5.0
2020-08-11 CVE-2020-13174 Improper Restriction of Rendered UI Layers or Frames vulnerability in Teradici Pcoip Management Console 20.01.1/20.04
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
network
teradici CWE-1021
4.3
2020-05-28 CVE-2020-13173 Race Condition vulnerability in Teradici Pcoip Graphics Agent and Pcoip Standard Agent
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing an application which acquires that named pipe.
local
low complexity
teradici CWE-362
4.6
2020-03-25 CVE-2020-10965 Insufficiently Protected Credentials vulnerability in Teradici Pcoip Management Console 19.11.1/20.01.0
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account.
network
teradici CWE-522
6.8