Vulnerability Description
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the login form, it would automatically send a second request to a RASHTML5Gateway/socket.io URI with something like "host":"192.168.###.###" in the POST data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Parallels | Remote Application Server | 18.0 |
Related Weaknesses (CWE)
References
- https://twitter.com/amadapa/status/1342407005110218753Third Party Advisory
- https://www.elladodelmal.com/2020/12/blue-team-red-team-como-parallels-ras.htmlExploitThird Party Advisory
- https://twitter.com/amadapa/status/1342407005110218753Third Party Advisory
- https://www.elladodelmal.com/2020/12/blue-team-red-team-como-parallels-ras.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-35710?
CVE-2020-35710 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the ...
How severe is CVE-2020-35710?
CVE-2020-35710 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35710?
Check the references section above for vendor advisories and patch information. Affected products include: Parallels Remote Application Server.