{"api_version":"1","generated_at":"2026-07-23T13:02:20+00:00","cve":"CVE-2020-13185","urls":{"html":"https://cve.report/CVE-2020-13185","api":"https://cve.report/api/cve/CVE-2020-13185.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-13185","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-13185"},"summary":{"title":"CVE-2020-13185","description":"Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability to execute sensitive functions without credentials.","state":"PUBLIC","assigner":"security@teradici.com","published_at":"2021-02-11 18:15:00","updated_at":"2021-02-25 22:24:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://advisory.teradici.com/security-advisories/69/","name":"https://advisory.teradici.com/security-advisories/69/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Teradici Security Advisories |","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-13185","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13185","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"13185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"teradici","cpe5":"cloud_access_connector","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13185","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"teradici","cpe5":"cloud_access_connector","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-13185","ASSIGNER":"security@teradici.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"- Cloud Access Connector - Cloud Access Connector Legacy","version":{"version_data":[{"version_value":"v18 and earlier"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-288: Authentication Bypass Using an Alternate Path or Channel"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://advisory.teradici.com/security-advisories/69/","url":"https://advisory.teradici.com/security-advisories/69/"}]},"description":{"description_data":[{"lang":"eng","value":"Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability to execute sensitive functions without credentials."}]}},"nvd":{"publishedDate":"2021-02-11 18:15:00","lastModifiedDate":"2021-02-25 22:24:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:teradici:cloud_access_connector:*:*:*:*:*:*:*:*","versionEndExcluding":"18","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"13185","Ordinal":"174364","Title":"CVE-2020-13185","CVE":"CVE-2020-13185","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"13185","Ordinal":"1","NoteData":"Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability to execute sensitive functions without credentials.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"13185","Ordinal":"2","NoteData":"2021-02-11","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"13185","Ordinal":"3","NoteData":"2021-02-11","Type":"Other","Title":"Modified"}]}}}