CVE detail
CVE-2020-7213 — CVE-2020-7213
Published 2020-01-21 · Modified 2026-06-17 · Vendor parallels · Product parallels · Source nvd
HIGH
severity
CVSS-derived band
0.0109
EPSS probability
exploitation probability, 30d
62.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References