Vulnerability Description
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teradici | Cloud Access Connector | <= 31 |
Related Weaknesses (CWE)
References
- https://advisory.teradici.com/security-advisories/70/Release NotesVendor Advisory
- https://advisory.teradici.com/security-advisories/70/Release NotesVendor Advisory
FAQ
What is CVE-2020-13186?
CVE-2020-13186 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID ...
How severe is CVE-2020-13186?
CVE-2020-13186 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13186?
Check the references section above for vendor advisories and patch information. Affected products include: Teradici Cloud Access Connector.