Teradici records
25 published records for vendor teradici.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-427 Uncontrolled Search Path Element2
- CWE-426 Untrusted Search Path2
- CWE-476 NULL Pointer Dereference2
- CWE-295 Improper Certificate Validation1
- CWE-312 Cleartext Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAll records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-25689No exploit | An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remotely execute code.teradici · pcoip soft client · CWE-787 | Critical9.8 | — | 1.6% | Feb 11, 2021 |
32Monitor | CVE-2020-10965No exploit | Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the dteradici · pcoip management console · CWE-287 | High8.1 | — | 1.5% | Mar 25, 2020 |
32Monitor | CVE-2022-1805No exploit | When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients.teradici · tera2 pcoip zero client firmware · CWE-295 | High8.1 | — | 0.6% | Jul 28, 2022 |
31Monitor | CVE-2020-13175No exploit | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 teradici · cloud access connector · CWE-98 | High7.5 | — | 1.7% | Aug 11, 2020 |
31Monitor | CVE-2019-20362No exploit | In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\teradici · pcoip standard agent · CWE-428 | High7.8 | — | 0.7% | Jan 8, 2020 |
31Monitor | CVE-2021-25699No exploit | The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, whiteradici · pcoip client · CWE-426 | High7.8 | — | 0.4% | Jul 21, 2021 |
31Monitor | CVE-2021-25698No exploit | The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, whicteradici · pcoip standard agent · CWE-426 | High7.8 | — | 0.4% | Jul 21, 2021 |
31Monitor | CVE-2017-20121No exploit | Teradici Management Console Database Management privileges managementteradici · pcoip management console · CWE-269 | High7.8 | — | 0.4% | Jun 30, 2022 |
31Monitor | CVE-2020-13177No exploit | The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does nteradici · graphics agent · CWE-427 | High7.8 | — | 0.4% | Aug 11, 2020 |
31Monitor | CVE-2021-25695No exploit | The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attackteradici · pcoip · CWE-782 | High7.8 | — | 0.3% | Jul 21, 2021 |
31Monitor | CVE-2021-25694No exploit | Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll.teradici · pcoip graphics agent · CWE-427 | High7.8 | — | 0.3% | May 13, 2021 |
31Monitor | CVE-2020-13173No exploit | Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 1teradici · pcoip graphics agent · CWE-362 | High7.8 | — | 0.2% | May 28, 2020 |
30Monitor | CVE-2021-25690No exploit | A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software.teradici · pcoip soft client · CWE-476 | High7.5 | — | 1.0% | Feb 11, 2021 |
30Monitor | CVE-2021-25693No exploit | An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer dereference.teradici · pcoip agent · CWE-476 | High7.5 | — | 1.0% | May 13, 2021 |
26Monitor | CVE-2020-13185No exploit | Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the nteradici · cloud access connector · CWE-288 | Medium6.5 | — | 1.0% | Feb 11, 2021 |
26Monitor | CVE-2020-13186No exploit | An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed ateradici · cloud access connector · CWE-352 | Medium6.5 | — | 0.4% | Feb 11, 2021 |
26Monitor | CVE-2020-13178No exploit | A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validateradici · graphics agent · CWE-345 | Medium6.7 | — | 0.2% | Aug 11, 2020 |
24Monitor | CVE-2020-13176No exploit | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16 teradici · cloud access connector · CWE-79 | Medium6.1 | — | 0.8% | Aug 11, 2020 |
24Monitor | CVE-2021-35451No exploit | In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web appteradici · pcoip management console · CWE-79 | Medium6.1 | — | 0.7% | Jul 7, 2021 |
24Monitor | CVE-2020-13174No exploit | The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which couteradici · pcoip management console · CWE-1021 | Medium6.1 | — | 0.7% | Aug 11, 2020 |
24Monitor | CVE-2020-13183No exploit | Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active seteradici · pcoip management console · CWE-79 | Medium6.1 | — | 0.6% | Aug 17, 2020 |
22Monitor | CVE-2020-13179No exploit | Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in teradici · graphics agent · CWE-200 | Medium5.5 | — | 0.3% | Aug 11, 2020 |
22Monitor | CVE-2021-25688No exploit | Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21teradici · pcoip graphics agent · CWE-532 | Medium5.5 | — | 0.3% | Feb 11, 2021 |
22Monitor | CVE-2021-25701No exploit | The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety teradici · pcoip client · CWE-400 | Medium5.5 | — | 0.2% | Jul 21, 2021 |
18Monitor | CVE-2021-25692No exploit | Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.teradici · pcoip connection manager and security gateway · CWE-312 | Medium4.6 | — | 0.2% | Apr 6, 2021 |
- CVE-2021-2568939Monitor
An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remotely execute code.
CriticalCVSS 9.8No exploitEPSS 2%teradici · pcoip soft clientFeb 11, 2021
- CVE-2020-1096532Monitor
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the d
HighCVSS 8.1No exploitEPSS 1%teradici · pcoip management consoleMar 25, 2020
- CVE-2022-180532Monitor
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients.
HighCVSS 8.1No exploitEPSS 1%teradici · tera2 pcoip zero client firmwareJul 28, 2022
- CVE-2020-1317531Monitor
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15
HighCVSS 7.5No exploitEPSS 2%teradici · cloud access connectorAug 11, 2020
- CVE-2019-2036231Monitor
In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\
HighCVSS 7.8No exploitEPSS 1%teradici · pcoip standard agentJan 8, 2020
- CVE-2021-2569931Monitor
The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, whi
HighCVSS 7.8No exploitEPSS 0%teradici · pcoip clientJul 21, 2021
- CVE-2021-2569831Monitor
The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, whic
HighCVSS 7.8No exploitEPSS 0%teradici · pcoip standard agentJul 21, 2021
- CVE-2017-2012131Monitor
Teradici Management Console Database Management privileges management
HighCVSS 7.8No exploitEPSS 0%teradici · pcoip management consoleJun 30, 2022
- CVE-2020-1317731Monitor
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does n
HighCVSS 7.8No exploitEPSS 0%teradici · graphics agentAug 11, 2020
- CVE-2021-2569531Monitor
The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attack
HighCVSS 7.8No exploitEPSS 0%teradici · pcoipJul 21, 2021
- CVE-2021-2569431Monitor
Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll.
HighCVSS 7.8No exploitEPSS 0%teradici · pcoip graphics agentMay 13, 2021
- CVE-2020-1317331Monitor
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 1
HighCVSS 7.8No exploitEPSS 0%teradici · pcoip graphics agentMay 28, 2020
- CVE-2021-2569030Monitor
A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software.
HighCVSS 7.5No exploitEPSS 1%teradici · pcoip soft clientFeb 11, 2021
- CVE-2021-2569330Monitor
An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer dereference.
HighCVSS 7.5No exploitEPSS 1%teradici · pcoip agentMay 13, 2021
- CVE-2020-1318526Monitor
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the n
MediumCVSS 6.5No exploitEPSS 1%teradici · cloud access connectorFeb 11, 2021
- CVE-2020-1318626Monitor
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed a
MediumCVSS 6.5No exploitEPSS 0%teradici · cloud access connectorFeb 11, 2021
- CVE-2020-1317826Monitor
A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly valida
MediumCVSS 6.7No exploitEPSS 0%teradici · graphics agentAug 11, 2020
- CVE-2020-1317624Monitor
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16
MediumCVSS 6.1No exploitEPSS 1%teradici · cloud access connectorAug 11, 2020
- CVE-2021-3545124Monitor
In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web app
MediumCVSS 6.1No exploitEPSS 1%teradici · pcoip management consoleJul 7, 2021
- CVE-2020-1317424Monitor
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which cou
MediumCVSS 6.1No exploitEPSS 1%teradici · pcoip management consoleAug 11, 2020
- CVE-2020-1318324Monitor
Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active se
MediumCVSS 6.1No exploitEPSS 1%teradici · pcoip management consoleAug 17, 2020
- CVE-2020-1317922Monitor
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in
MediumCVSS 5.5No exploitEPSS 0%teradici · graphics agentAug 11, 2020
- CVE-2021-2568822Monitor
Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21
MediumCVSS 5.5No exploitEPSS 0%teradici · pcoip graphics agentFeb 11, 2021
- CVE-2021-2570122Monitor
The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety
MediumCVSS 5.5No exploitEPSS 0%teradici · pcoip clientJul 21, 2021
- CVE-2021-2569218Monitor
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.
MediumCVSS 4.6No exploitEPSS 0%teradici · pcoip connection manager and security gatewayApr 6, 2021