PT-2021-9566 · Teradici · Teradici Cloud Access Connector

Published

2021-02-11

·

Updated

2021-02-22

·

CVE-2020-13186

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Teradici Cloud Access Connector versions prior to v31
Description A missing Anti CSRF mechanism was discovered in a specific web form of the Teradici Cloud Access Connector, allowing an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.
Recommendations For versions prior to v31, update to a version that includes the Anti CSRF mechanism to prevent exploitation. As a temporary workaround, consider restricting access to the specific web form until a patch is available. Avoid using the machineID and user GUID in the affected web form until the issue is resolved.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13186

Affected Products

Teradici Cloud Access Connector