CVE-2020-8968
Summary
| CVE | CVE-2020-8968 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-17 17:15:00 UTC |
| Updated | 2023-11-20 10:15:00 UTC |
| Description | Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to recover the profile password. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Parallels | Remote Application Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.incibe.es/en/incibe-cert/notices/aviso/parallels-remote-application-ser... | www.incibe.es | ||
| Parallels Remote Application Server credentials management errors | INCIBE-CERT | CONFIRM | www.incibe-cert.es | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Francisco Palma, Diego León and David Jiménez
There are currently no legacy QID mappings associated with this CVE.