PT-2020-19468 · Parallels · Parallels
Published
2020-01-21
·
Updated
2020-01-29
·
CVE-2020-7213
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Parallels versions prior to 13
Description
The issue allows for man-in-the-middle attacks due to the use of cleartext HTTP as part of the update process. Users of out-of-date versions are presented with a pop-up window for a parallels updates.xml file on the http://update.parallels.com web site.
Recommendations
For versions prior to 13, update to version 13 or later to resolve the issue. As a temporary workaround, consider restricting access to the http://update.parallels.com web site to minimize the risk of exploitation.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parallels