« Back to list

CVE-2021-25690

Status: ModifiedHigh (7.5)—

A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2021-25690",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@teradici.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "- PCoIP Soft Client for Windows - PCoIP Soft Client for Linux - PCoIP Soft Client for OSX",
          "versions": [
            {
              "status": "affected",
              "version": "20.07.2 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-11T18:15:17.877",
  "references": [
    {
      "url": "https://advisory.teradici.com/security-advisories/74/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@teradici.com"
    },
    {
      "url": "https://advisory.teradici.com/security-advisories/74/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software."
    },
    {
      "lang": "es",
      "value": "Una desreferencia del puntero null en las versiones de Teradici PCoIP Soft Client versiones anteriores a 20.07.3, podría permitir a un atacante bloquear el software"
    }
  ],
  "lastModified": "2026-06-17T03:42:21.713",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:teradici:pcoip_soft_client:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2ECE59B0-D8DB-439C-A788-7973043BA857",
              "versionEndIncluding": "20.07.2"
            },
            {
              "criteria": "cpe:2.3:a:teradici:pcoip_soft_client:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "717E3CB8-DFCD-4C51-8E9C-4E036FE41430",
              "versionEndIncluding": "20.07.2"
            },
            {
              "criteria": "cpe:2.3:a:teradici:pcoip_soft_client:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EA30CDD-C694-4CE7-94B8-F3BF02C34CBC",
              "versionEndIncluding": "20.07.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@teradici.com"
}