9.8
CVE-2022-27518
- EPSS 12.37%
- Published 13.12.2022 17:15:14
- Last modified 14.02.2025 16:45:23
- Source secure@citrix.com
- Teams watchlist Login
- Open Login
Unauthenticated remote arbitrary code execution
Data is provided by the National Vulnerability Database (NVD)
Citrix ≫ Application Delivery Controller Firmware SwEditionfips Version >= 12.1 < 12.1-55.291
Citrix ≫ Application Delivery Controller Firmware SwEditionndcpp Version >= 12.1 < 12.1-55.291
Citrix ≫ Application Delivery Controller Firmware Version >= 12.1 < 12.1-65.25
Citrix ≫ Application Delivery Controller Firmware Version >= 13.0 < 13.0-58.32
Citrix ≫ Gateway Firmware Version >= 12.1 < 12.1-65.25
Citrix ≫ Gateway Firmware Version >= 13.0 < 13.0-58.32
13.12.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
VulnerabilityCitrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.
DescriptionApply updates per vendor instructions.
Required actions13.12.2022: CERT.at Warnung
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 12.37% | 0.936 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
secure@citrix.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-664 Improper Control of a Resource Through its Lifetime
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.