Vulnerabilities > Citrix

DATE CVE VULNERABILITY TITLE RISK
2020-11-16 CVE-2020-8273 OS Command Injection vulnerability in Citrix Sd-Wan
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
network
low complexity
citrix CWE-78
8.8
2020-11-16 CVE-2020-8272 Improper Authentication vulnerability in Citrix Sd-Wan
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
network
low complexity
citrix CWE-287
7.5
2020-11-16 CVE-2020-8271 Path Traversal vulnerability in Citrix Sd-Wan
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
network
low complexity
citrix CWE-22
critical
9.8
2020-11-16 CVE-2020-8270 OS Command Injection vulnerability in Citrix Virtual Apps and Desktops 1903/1912/2006
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
network
low complexity
citrix CWE-78
8.8
2020-11-16 CVE-2020-8269 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops, Xenapp and Xendesktop
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
network
low complexity
citrix CWE-269
8.8
2020-09-18 CVE-2020-8253 Improper Authentication vulnerability in Citrix Xenmobile Server
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.
network
low complexity
citrix CWE-287
7.5
2020-09-18 CVE-2020-8247 Improper Privilege Management vulnerability in Citrix products
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.
network
low complexity
citrix CWE-269
8.8
2020-09-18 CVE-2020-8246 Resource Exhaustion vulnerability in Citrix products
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to a denial of service attack originating from the management network.
network
low complexity
citrix CWE-400
7.5
2020-09-18 CVE-2020-8245 Cross-site Scripting vulnerability in Citrix products
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b leads to an HTML Injection attack against the SSL VPN web portal.
network
low complexity
citrix CWE-79
6.1
2020-09-18 CVE-2020-8200 Improper Authentication vulnerability in Citrix Storefront Server
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
network
low complexity
citrix CWE-287
6.5