CVE-2020-35710
MEDIUMParallels Remote Application Server 18 - Unauthenticated Intranet IP Address Exposure via Login Form
Title source: llmDescription
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the login form, it would automatically send a second request to a RASHTML5Gateway/socket.io URI with something like "host":"192.168.###.###" in the POST data.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.elladodelmal.com/2020/12/blue-team-red-team-como-parallels-ras.html
Third Party Advisory x_refsource_misc
https://twitter.com/amadapa/status/1342407005110218753
Scores
CVSS v3
5.3
EPSS
0.0166
EPSS Percentile
73.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
parallels/remote_application_server
18.0
Published
Dec 25, 2020
Tracked Since
Feb 18, 2026