Vulnerabilities > Citrix

DATE CVE VULNERABILITY TITLE RISK
2020-06-08 CVE-2020-13885 Incorrect Default Permissions vulnerability in Citrix Workspace APP 1909/1911/2002
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
local
low complexity
citrix CWE-276
7.2
2020-06-08 CVE-2020-13884 Incorrect Default Permissions vulnerability in Citrix Workspace APP 1909/1911/2002
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
local
low complexity
citrix CWE-276
7.2
2020-05-07 CVE-2020-8983 Path Traversal vulnerability in Citrix Sharefile Storagezones Controller
An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution.
network
low complexity
citrix CWE-22
5.0
2020-05-07 CVE-2020-8982 Path Traversal vulnerability in Citrix Sharefile Storagezones Controller
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020.
network
low complexity
citrix CWE-22
5.0
2020-05-07 CVE-2020-7473 Path Traversal vulnerability in Citrix Sharefile Storagezones Controller
In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users.
network
low complexity
citrix CWE-22
5.0
2020-03-16 CVE-2020-6175 Improper Certificate Validation vulnerability in Citrix Sd-Wan Center and Netscaler Sd-Wan Center
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
network
citrix CWE-295
4.3
2020-03-10 CVE-2019-11345 Cross-site Scripting vulnerability in Citrix Sd-Wan Center and Netscaler Sd-Wan Center
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.
network
citrix CWE-79
4.3
2020-03-06 CVE-2020-10112 HTTP Request Smuggling vulnerability in Citrix Gateway Firmware 11.1/12.0/12.1
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning.
network
low complexity
citrix CWE-444
5.4
2020-03-06 CVE-2020-10111 HTTP Request Smuggling vulnerability in Citrix Gateway Firmware 11.1/12.0/12.1
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests.
network
low complexity
citrix CWE-444
7.5
2020-03-06 CVE-2020-10110 Unspecified vulnerability in Citrix Gateway Firmware 11.1/12.0/12.1
Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching.
network
low complexity
citrix
5.3