High severity8.1NVD Advisory· Published Nov 23, 2022· Updated Jun 17, 2026
CVE-2022-40870
CVE-2022-40870
Description
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:parallels:remote_application_server:18.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:parallels:remote_application_server:18.0:*:*:*:*:*:*:*
- (no CPE)range: 18.0
- Parallels/Remote Application Serverdescription
Patches
Vulnerability mechanics
References
2- github.com/IthacaLabs/Parallels/blob/main/ParallelsRemoteApplicationServer/HHI_CVE-2022-40870.txtnvdExploitThird Party Advisory
- github.com/IthacaLabs/Parallels/tree/main/ParallelsRemoteApplicationServernvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.