7.5

CVE-2016-4810

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
CitrixXenapp Version7.5
CitrixXenapp Version7.6
CitrixXendesktop Version7.0
CitrixXendesktop Version7.1
CitrixXendesktop Version7.5
CitrixXendesktop Version7.6
CitrixXendesktop Version7.6 Updatefp1
CitrixXendesktop Version7.6 Updatefp2
CitrixXendesktop Version7.6 Updatefp3
CitrixXendesktop Version7.6 Updateltsr
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.414
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.