Vulnerabilities
Vulnerable Software
Citrix:  Security Vulnerabilities
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
CVSS Score
5.3
EPSS Score
0.003
Published
2022-06-16
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
CVSS Score
7.1
EPSS Score
0.001
Published
2022-05-26
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
CVSS Score
8.8
EPSS Score
0.008
Published
2022-04-19
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-04-15
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
CVSS Score
6.1
EPSS Score
0.006
Published
2022-04-13
Reflected cross site scripting (XSS)
CVSS Score
6.1
EPSS Score
0.007
Published
2022-04-13
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
CVSS Score
2.7
EPSS Score
0.002
Published
2022-04-13
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
CVSS Score
8.8
EPSS Score
0.061
Published
2022-04-13
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
CVSS Score
7.2
EPSS Score
0.025
Published
2022-04-13
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.
CVSS Score
4.4
EPSS Score
0.0
Published
2022-03-10


Contact Us

Shodan ® - All rights reserved