← Volver a CVEs
CVE-2020-15860
CRITICAL9.9
Descripcion
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.
Detalles CVE
Puntuacion CVSS v3.19.9
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado7/24/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
parallels:remote_application_server
Referencias
https://kb.parallels.com/en/125112(cve@mitre.org)
https://kb.parallels.com/en/125112(af854a3a-2127-422b-91ae-364da2661108)
https://www.coresecurity.com/core-labs/advisories/parallels-ras-os-command-execution(af854a3a-2127-422b-91ae-364da2661108)
https://www.parallels.com/products/ras/remote-application-server/(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.