PT-2021-9566 · Teradici · Teradici Cloud Access Connector
Published
2021-02-11
·
Updated
2021-02-22
·
CVE-2020-13186
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Teradici Cloud Access Connector versions prior to v31
Description
A missing Anti CSRF mechanism was discovered in a specific web form of the Teradici Cloud Access Connector, allowing an attacker with knowledge of both a
machineID and user GUID to modify data if a user clicked a malicious link.Recommendations
For versions prior to v31, update to a version that includes the Anti CSRF mechanism to prevent exploitation. As a temporary workaround, consider restricting access to the specific web form until a patch is available. Avoid using the
machineID and user GUID in the affected web form until the issue is resolved.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teradici Cloud Access Connector