9.1
CVE-2018-18571
- EPSS 0.34%
- Veröffentlicht 05.06.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:10
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Xenmobile Server Version10.8.0 Update-
Citrix ≫ Xenmobile Server Version10.8.0 Updaterolling_patch1
Citrix ≫ Xenmobile Server Version10.8.0 Updaterolling_patch2
Citrix ≫ Xenmobile Server Version10.8.0 Updaterolling_patch3
Citrix ≫ Xenmobile Server Version10.8.0 Updaterolling_patch4
Citrix ≫ Xenmobile Server Version10.8.0 Updaterolling_patch5
Citrix ≫ Xenmobile Server Version10.9.0 Update-
Citrix ≫ Xenmobile Server Version10.9.0 Updaterolling_patch1
Citrix ≫ Xenmobile Server Version10.9.0 Updaterolling_patch2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.533 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.