HIGH🇵🇱 Wersja polska

CVE-2020-8968

CVSS 7.1v3.1pub. 2021-12-17upd. 2024-11-21

Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to recover the profile password.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Parallels Remote Application Server

    APP
    Parallels
    15.5 – 17.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-45894CRITICAL10.0PL ✓same product

RCE w Parallels Remote Application Server przez brak segmentacji aplikacji

CVE-2020-15860CRITICAL9.9PL ✓same product

RCE w Parallels Remote Application Server — błąd logiki biznesowej

CVE-2025-0413HIGH7.8same product

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulne...

CVE-2022-40870HIGH8.1same product

The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. Th...

CVE-2017-9447HIGH7.5same product

In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due...