When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tera2_pcoip_zero_client_firmware | Teradici | * | 22.01.5 (excluding) |
Tera2_pcoip_zero_client_firmware | Teradici | 22.04 (including) | 22.04 (including) |