Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2020-13175 : What You Need to Know

Learn about CVE-2020-13175 affecting Teradici Cloud Access Connector and Cloud Access Connector Legacy versions. Discover the impact, affected systems, and mitigation steps.

Teradici Cloud Access Connector and Cloud Access Connector Legacy versions prior to April 20, 2020, are affected by a local file inclusion vulnerability that can lead to LDAP credential leakage.

Understanding CVE-2020-13175

The Management Interface of Teradici's Cloud Access Connector and Cloud Access Connector Legacy is vulnerable to a specific type of attack.

What is CVE-2020-13175?

The vulnerability in the Management Interface of Teradici Cloud Access Connector and Cloud Access Connector Legacy versions prior to April 20, 2020, allows unauthenticated remote attackers to leak LDAP credentials through a crafted HTTP request.

The Impact of CVE-2020-13175

This vulnerability poses a significant risk as it can result in the exposure of sensitive LDAP credentials to unauthorized parties.

Technical Details of CVE-2020-13175

Teradici Cloud Access Connector and Cloud Access Connector Legacy are affected by a critical security issue.

Vulnerability Description

The local file inclusion vulnerability in the Management Interface of the affected versions enables attackers to extract LDAP credentials remotely.

Affected Systems and Versions

        Products: Cloud Access Connector, Cloud Access Connector Legacy
        Versions: Cloud Access Connector Legacy prior to April 20, 2020, Cloud Access Connector v15 and earlier

Exploitation Mechanism

Attackers can exploit this vulnerability by sending a specially crafted HTTP request to the Management Interface, leading to the leakage of LDAP credentials.

Mitigation and Prevention

It is crucial to take immediate action to secure systems against CVE-2020-13175.

Immediate Steps to Take

        Update Teradici Cloud Access Connector and Cloud Access Connector Legacy to versions released after April 20, 2020.
        Monitor network traffic for any suspicious activities that might indicate an ongoing attack.

Long-Term Security Practices

        Regularly review and update security configurations to prevent similar vulnerabilities in the future.
        Conduct security training for employees to enhance awareness of potential threats.

Patching and Updates

        Apply patches and updates provided by Teradici to address the local file inclusion vulnerability and enhance system security.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now