Description
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client.
References
https://support.hp.com/us-en/document/ish_6545906-6545930-16/hpsbhf03794
PatchVendor Advisory
https://support.hp.com/us-en/document/ish_6545906-6545930-16/hpsbhf03794
PatchVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
8.1 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-07-28T13:15:07.553Z
3 years agoLast modified
2024-11-21T05:41:30.410Z
1 year ago