9.8
CVE-2022-27518
- EPSS 12.37%
- Veröffentlicht 13.12.2022 17:15:14
- Zuletzt bearbeitet 14.02.2025 16:45:23
- Quelle secure@citrix.com
- Teams Watchlist Login
- Unerledigt Login
Unauthenticated remote arbitrary code execution
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Application Delivery Controller Firmware SwEditionfips Version >= 12.1 < 12.1-55.291
Citrix ≫ Application Delivery Controller Firmware SwEditionndcpp Version >= 12.1 < 12.1-55.291
Citrix ≫ Application Delivery Controller Firmware Version >= 12.1 < 12.1-65.25
Citrix ≫ Application Delivery Controller Firmware Version >= 13.0 < 13.0-58.32
Citrix ≫ Gateway Firmware Version >= 12.1 < 12.1-65.25
Citrix ≫ Gateway Firmware Version >= 13.0 < 13.0-58.32
13.12.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
SchwachstelleCitrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen13.12.2022: CERT.at Warnung
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 12.37% | 0.936 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
secure@citrix.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-664 Improper Control of a Resource Through its Lifetime
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.