CVE-2020-13175
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/08/2020
Last modified:
14/08/2020
Description
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially crafted HTTP request.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:teradici:cloud_access_connector:*:*:*:*:*:*:*:* | 15 (including) | |
| cpe:2.3:a:teradici:cloud_access_connector_legacy:*:*:*:*:*:*:*:* | 2020-04-20 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



