Remote Application Exposure in Parallels RAS
CVE-2020-35710

5.3MEDIUM

Key Information:

Vendor

Parallels

Vendor
CVE Published:
25 December 2020

What is CVE-2020-35710?

The Parallels Remote Application Server 18 exposes the intranet IP address during the login process. When a user attempts to log in, even with no credentials provided, the login form leaks the internal IP address back to the attacker's client. This occurs as the system processes the initial request and subsequently sends a POST request containing the intranet IP in the 'host' value to a different endpoint. This vulnerability can enable remote attackers to gather sensitive network information, which may be exploited for further attacks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.