Palo Alto Networks Security Advisories / CVE-2017-5328

CVE-2017-5328 Spoofing in Terminal Services Agent

047910
Severity 7.5 · HIGH
Attack Vector NETWORK
Attack Complexity LOW
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact HIGH
Availability Impact NONE

Description

A spoofing vulnerability exists in Terminal Services Agent (ref # PAN-67269 / CVE-2017-5328).

Terminal Services Agent contains a vulnerability whereby a user can spoof the identity of another authenticated user.

This issue affects Terminal Services Agent 6.0; Terminal Services Agent 7.0.6 and earlier

Product Status

VersionsAffectedUnaffected
Terminal Services Agent 7.0<= 7.0.6>= 7.0.7

Severity: HIGH

CVSSv3.1 Base Score: 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Weakness Type

Solution

Terminal Services Agent 7.0.7 and later

Workarounds and Mitigations

N/A

© 2020 Palo Alto Networks, Inc. All rights reserved.