CVE-2020-13173
Summary
| CVE | CVE-2020-13173 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-28 22:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing an application which acquires that named pipe. |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Teradici | Pcoip Graphics Agent | All | All | All | All |
| Application | Teradici | Pcoip Standard Agent | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Teradici Security Advisories | | CONFIRM | advisory.teradici.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.