6.1
CVE-2020-13174
- EPSS 0.66%
- Veröffentlicht 11.08.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:48
- Erkennungen
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teradici ≫ Pcoip Management Console Version 20.01.1
Teradici ≫ Pcoip Management Console Version 20.04
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.467 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://advisory.teradici.com/security-advisories/58/