CVE-2020-15860
Estado: ModificadaCrítica (9.9)—
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.01%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- https://kb.parallels.com/en/125112
- https://www.coresecurity.com/core-labs/advisories/parallels-ras-os-command-execution
- https://www.parallels.com/products/ras/remote-application-server/
- https://kb.parallels.com/en/125112
- https://www.coresecurity.com/core-labs/advisories/parallels-ras-os-command-execution
- https://www.parallels.com/products/ras/remote-application-server/
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-15860",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-07-24T16:15:11.973",
"references": [
{
"url": "https://kb.parallels.com/en/125112",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.coresecurity.com/core-labs/advisories/parallels-ras-os-command-execution",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.parallels.com/products/ras/remote-application-server/",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://kb.parallels.com/en/125112",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.coresecurity.com/core-labs/advisories/parallels-ras-os-command-execution",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.parallels.com/products/ras/remote-application-server/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm."
},
{
"lang": "es",
"value": "Parallels Remote Application Server (RAS) versión 17.1.1, presenta un Error de Lógica de Negocios que causa una ejecución de código remota. Permite a un usuario autenticado ejecutar cualquier aplicación en el sistema operativo backend por medio de la aplicación web, a pesar de que la aplicación afectada no ha sido publicada. Además, se detectó que es posible acceder a cualquier host en el dominio interno, inclusive si no tiene aplicaciones publicadas o si el host mencionado ya no está asociado con esa granja de servidores"
}
],
"lastModified": "2026-06-17T02:57:18.467",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:parallels:remote_application_server:17.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6B88580-D3C2-40F4-9F5E-15F172C5985A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}