Vulnerabilities
Vulnerable Software
Citrix:  Security Vulnerabilities
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
CVSS Score
6.5
EPSS Score
0.046
Published
2019-07-11
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
CVSS Score
9.8
EPSS Score
0.006
Published
2019-06-24
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
CVSS Score
10.0
EPSS Score
0.005
Published
2019-06-05
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
CVSS Score
9.1
EPSS Score
0.003
Published
2019-06-05
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.
CVSS Score
9.8
EPSS Score
0.519
Published
2019-06-03
CVE-2019-11634
Known exploited
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVSS Score
9.8
EPSS Score
0.562
Published
2019-05-22
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.
CVSS Score
7.5
EPSS Score
0.006
Published
2019-05-22
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-05-13
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).
CVSS Score
5.9
EPSS Score
0.003
Published
2019-05-13
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
CVSS Score
5.9
EPSS Score
0.001
Published
2019-05-08


Contact Us

Shodan ® - All rights reserved