9.6
CVE-2022-27513
- EPSS 0.41%
- Veröffentlicht 08.11.2022 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:55:52
- Quelle secure@citrix.com
- Teams Watchlist Login
- Unerledigt Login
Remote desktop takeover via phishing
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Application Delivery Controller Firmware SwEdition- Version >= 12.1 < 12.1-65.21
Citrix ≫ Application Delivery Controller Firmware SwEdition- Version >= 13.0 < 13.0-88.12
Citrix ≫ Application Delivery Controller Firmware SwEdition- Version >= 13.1 < 13.1-33.47
Citrix ≫ Application Delivery Controller Firmware SwEditionfips Version >= 12.1 < 12.1-55.289
Citrix ≫ Application Delivery Controller Firmware SwEditionndcpp Version >= 12.1 < 12.1-55.289
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.41% | 0.604 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
secure@citrix.com | 8.3 | 1.6 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.