Vulnerability Description
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teradici | Pcoip Management Console | 20.01.1 |
Related Weaknesses (CWE)
References
- https://advisory.teradici.com/security-advisories/58/PatchVendor Advisory
- https://advisory.teradici.com/security-advisories/58/PatchVendor Advisory
FAQ
What is CVE-2020-13174?
CVE-2020-13174 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicio...
How severe is CVE-2020-13174?
CVE-2020-13174 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13174?
Check the references section above for vendor advisories and patch information. Affected products include: Teradici Pcoip Management Console.