← Back

CVE-2022-1805

nvd nist
Published: Jul 28, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client.

Affected (2)

1 product
Tera2 Pcoip Zero Client Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Teradici
Before 22.01.5
Version 22.04
Running on/withPlatform Versions
Teradici
Tera2 Pcoip Zero Client
All versions

References (2)

Source: hp-security-alert@hp.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.