Security Advisory

CVE-2022-1805

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-07-28 14:21:09
Last updated 2024-08-03 00:16:59
Assigner hp
State PUBLISHED

Description

When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client.