CVE-2020-15860
moderate-risk
Published 2020-07-24
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.
Do I need to act?
~
3.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.9/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Remote Application Server
Affected Vendors
References (6)
Vendor Advisory
https://kb.parallels.com/en/125112
Vendor Advisory
https://kb.parallels.com/en/125112
45
/ 100
moderate-risk
Severity
33/34 · Critical
Exploitability
7/34 · Low
Exposure
5/34 · Minimal