Teradici (HP)

First CVE: May 28, 2020Active for: 6 years
20
CVEs Published
More CVEs Published than 39% of tracked CNAs
10.0
Avg CVEs / Year
More Avg CVEs / Year than 54% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Teradici (HP) as a CNA, 100.0% affect products that Teradici (HP) develops as a vendor.

100.0%
Self-reported: 20Third-party: 0

Of all the CVEs published that affect products developed by Teradici (HP), 80.0% are self-published by Teradici (HP) as a CNA.

80.0%
20.0%
Self-published: 20Published by other CNAs: 5

Trends Over Time

The number and severity of CVEs published by Teradici (HP) over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2020
6 years ago
Most Recent CVE
Jul 21, 2021
1,829 days ago

Top CVEs

All CVEs published by Teradici (HP) as a CNA, regardless of affected vendor or product.

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remotely execute code.
Feb 11, 20219.828NONO
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector)
Aug 11, 20207.525NONO
The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the
Jul 21, 20217.824NONO
The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the
Jul 21, 20217.824NONO
The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the
Jul 21, 20217.824NONO
An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer dereference.
May 13, 20217.524NONO
Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll and redirect pixels elsewhere.
May 13, 20217.824NONO
A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software.
Feb 11, 20217.523NONO
Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active session if the user is exposed to a malici
Aug 17, 20206.121NONO
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, wh
Feb 11, 20216.520NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA20 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local10 (50.0%)
Network9 (45.0%)
Unknown0 (0.0%)
Physical1 (5.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (55.0%)
Unknown0 (0.0%)
Required9 (45.0%)
Privileges Required
Low5 (25.0%)
High1 (5.0%)
None14 (70.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Teradici (HP) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Teradici (HP) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs