Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-9497

EPSS 0.08% · P24
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-9497

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Guacamole 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Guacamole是美国阿帕奇(Apache)软件基金会的一款无客户端的远程桌面网关。该产品支持VNC、RDP和SSH等协议。 Apache Guacamole 1.1.0及之前版本中存在安全漏洞,该漏洞源于程序未正确验证通过静态虚拟通道从RDP服务器接收的数据。攻击者可借助特制的PDU利用该漏洞获取信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Apache Guacamole Apache Guacamole 1.1.0 and older -

II. Public POCs for CVE-2020-9497

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-9497

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-07-02 · 19 CVEs total

CVE-2020-13653Zimbra Collaboration Suite 跨站脚本漏洞
CVE-2020-8161RubyGem Rack 路径遍历漏洞
CVE-2020-15503LibRaw 输入验证错误漏洞
CVE-2020-15502DuckDuckGo application 信息泄露漏洞
CVE-2020-5911F5 NGINX Controller 安全漏洞
CVE-2020-5910F5 NGINX Controller 授权问题漏洞
CVE-2020-5909F5 NGINX Controller 信任管理问题漏洞
CVE-2020-9498Apache Guacamole 缓冲区错误漏洞
CVE-2020-12119Ledger Live 安全漏洞
CVE-2020-15469QEMU 代码问题漏洞
CVE-2020-14092WordPress CodePeople Payment Form for PayPal Pro SQL注入漏洞
CVE-2019-20894Containous Traefik 信任管理问题漏洞
CVE-2020-8185Rails 资源管理错误漏洞
CVE-2020-8163Ruby on Rails 代码注入漏洞
CVE-2020-8188Ubiquiti UniFi Protect 命令注入漏洞
CVE-2020-8166Ruby on Rails 跨站请求伪造漏洞
CVE-2020-8179Nextcloud Deck 访问控制错误漏洞
CVE-2020-8176koa-shopify-auth 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-9497

No comments yet


Leave a comment