CVE-2022-1805
Estado: ModificadaAlta (8.1)—
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.62%
- Percentil entre todas las CVEs puntuadas: 48
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-295
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-1805",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "hp-security-alert@hp.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Tera2 Zero Client",
"versions": [
{
"status": "affected",
"version": "Firmware version 22.04 and earlier"
}
]
}
]
}
],
"published": "2022-07-28T15:15:07.553",
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_6545906-6545930-16/hpsbhf03794",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "hp-security-alert@hp.com"
},
{
"url": "https://support.hp.com/us-en/document/ish_6545906-6545930-16/hpsbhf03794",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client."
},
{
"lang": "es",
"value": "Cuando es conectado a Amazon Workspaces, el SHA256 presentado por el aprovisionador de conexiones de AWS no es verificado completamente por Zero Clients. El problema podría ser explotado por un adversario que coloque un MITM (Man in the Middle) entre un cliente cero y el aprovisionador de sesiones de AWS en la red. Este problema sólo es aplicable cuando es conectado a un espacio de trabajo de Amazon desde un cliente cero PCoIP"
}
],
"lastModified": "2026-06-17T04:23:08.733",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:teradici:tera2_pcoip_zero_client_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BDC5949-06FB-493B-BA9C-CA37BC611F28",
"versionEndExcluding": "22.01.5"
},
{
"criteria": "cpe:2.3:o:teradici:tera2_pcoip_zero_client_firmware:22.04:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "652204B8-1CF6-4A8B-8D29-EACFA05BA212"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:teradici:tera2_pcoip_zero_client:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "91376750-D525-48A7-B775-6DFB7953C05D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "hp-security-alert@hp.com"
}