Vulnerabilities > Citrix

DATE CVE VULNERABILITY TITLE RISK
2022-04-13 CVE-2022-27506 Use of Hard-coded Credentials vulnerability in Citrix products
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
network
low complexity
citrix CWE-798
6.8
2022-04-13 CVE-2021-44520 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
network
low complexity
citrix CWE-77
critical
9.0
2022-04-13 CVE-2022-26151 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
network
low complexity
citrix CWE-77
7.2
2022-03-10 CVE-2022-26355 Exposure of Resource to Wrong Sphere vulnerability in Citrix Federated Authentication Service
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP).
local
citrix CWE-668
1.9
2022-02-09 CVE-2022-21825 Unspecified vulnerability in Citrix Workspace
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
local
low complexity
citrix
7.8
2021-12-07 CVE-2021-22955 Resource Exhaustion vulnerability in Citrix Application Delivery Controller Firmware and Gateway
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
network
citrix CWE-400
4.3
2021-12-07 CVE-2021-22956 Resource Exhaustion vulnerability in Citrix products
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
network
citrix CWE-400
4.3
2021-09-23 CVE-2021-22941 Unspecified vulnerability in Citrix Sharefile Storagezones Controller
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
network
low complexity
citrix
critical
10.0
2021-08-16 CVE-2021-22932 Missing Encryption of Sensitive Data vulnerability in Citrix Sharefile Storagezones Controller
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled.
network
low complexity
citrix CWE-311
5.0
2021-08-05 CVE-2021-22919 Allocation of Resources Without Limits or Throttling vulnerability in Citrix products
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO.
network
low complexity
citrix CWE-770
5.0