Added |
CVSS V3.1 |
|
NIST AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
Added |
CVSS V2 |
|
NIST (AV:N/AC:M/Au:N/C:P/I:N/A:N)
|
Added |
CWE |
|
NIST CWE-200
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:* versions up to (including) 1.1.0
|
Changed |
Reference Type |
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44525 No Types Assigned
|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44525 Third Party Advisory
|
Changed |
Reference Type |
https://lists.apache.org/thread.html/r066543f0565e97b27c0dfe27e93e8a387b99e1e35764000224ed96e7@%3Cuser.guacamole.apache.org%3E No Types Assigned
|
https://lists.apache.org/thread.html/r066543f0565e97b27c0dfe27e93e8a387b99e1e35764000224ed96e7@%3Cuser.guacamole.apache.org%3E Mailing List, Vendor Advisory
|
Changed |
Reference Type |
https://lists.apache.org/thread.html/r181b1d5b1acb31cfa69f41b2c86ed3a2cb0b5bc09c2cbd31e9e7c847@%3Cuser.guacamole.apache.org%3E No Types Assigned
|
https://lists.apache.org/thread.html/r181b1d5b1acb31cfa69f41b2c86ed3a2cb0b5bc09c2cbd31e9e7c847@%3Cuser.guacamole.apache.org%3E Mailing List, Vendor Advisory
|
Changed |
Reference Type |
https://lists.apache.org/thread.html/r3f071de70ea1facd3601e0fa894e6cadc960627ee7199437b5a56f7f@%3Cannounce.apache.org%3E No Types Assigned
|
https://lists.apache.org/thread.html/r3f071de70ea1facd3601e0fa894e6cadc960627ee7199437b5a56f7f@%3Cannounce.apache.org%3E Mailing List, Vendor Advisory
|
Changed |
Reference Type |
https://lists.apache.org/thread.html/r65f75d3d65d1af68141f42071ebb27dda24af3e45570e593c1dbd81f%40%3Cannounce.guacamole.apache.org%3E No Types Assigned
|
https://lists.apache.org/thread.html/r65f75d3d65d1af68141f42071ebb27dda24af3e45570e593c1dbd81f%40%3Cannounce.guacamole.apache.org%3E Mailing List, Vendor Advisory
|
Changed |
Reference Type |
https://research.checkpoint.com/2020/apache-guacamole-rce/ No Types Assigned
|
https://research.checkpoint.com/2020/apache-guacamole-rce/ Third Party Advisory
|
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism
|