9.8

CVE-2022-27518

Warnung

Unauthenticated remote arbitrary code execution

Unauthenticated remote arbitrary code execution
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Application Delivery Controller Firmware SwEdition fips Version >= 12.1 < 12.1-55.291
Citrix ≫ Application Delivery Controller Firmware SwEdition ndcpp Version >= 12.1 < 12.1-55.291
Citrix ≫ Application Delivery Controller Firmware Version >= 12.1 < 12.1-65.25
Citrix ≫ Application Delivery Controller Firmware Version >= 13.0 < 13.0-58.32
Citrix ≫ Gateway Firmware Version >= 12.1 < 12.1-65.25
   Citrix ≫ Gateway Version -
Citrix ≫ Gateway Firmware Version >= 13.0 < 13.0-58.32
   Citrix ≫ Gateway Version -

13.12.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Schwachstelle

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.88% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
secure@citrix.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-664 Improper Control of a Resource Through its Lifetime

The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

https://support.citrix.com/article/CTX474995
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27518
US Government Resource