Vulnerabilities > Citrix > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-13 CVE-2022-27503 Cross-site Scripting vulnerability in Citrix Storefront Server
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
network
low complexity
citrix CWE-79
6.1
2022-04-13 CVE-2022-27505 Cross-site Scripting vulnerability in Citrix products
Reflected cross site scripting (XSS)
network
low complexity
citrix CWE-79
6.1
2022-03-10 CVE-2022-26355 Exposure of Resource to Wrong Sphere vulnerability in Citrix Federated Authentication Service 10.6/7.17
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP).
local
low complexity
citrix CWE-668
4.4
2021-08-05 CVE-2021-22920 Unspecified vulnerability in Citrix Application Delivery Management and Gateway
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO.
network
low complexity
citrix
6.5
2021-06-16 CVE-2020-8299 Resource Exhaustion vulnerability in Citrix products
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment.
low complexity
citrix CWE-400
6.5
2021-06-16 CVE-2020-8300 Unspecified vulnerability in Citrix products
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session.
network
low complexity
citrix
6.5
2021-01-06 CVE-2020-8275 Improper Privilege Management vulnerability in Citrix Secure Mail
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail.
network
low complexity
citrix CWE-269
4.3
2021-01-06 CVE-2020-8274 Code Injection vulnerability in Citrix Secure Mail
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail.
network
low complexity
citrix CWE-94
6.5
2020-09-18 CVE-2020-8245 Cross-site Scripting vulnerability in Citrix products
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b leads to an HTML Injection attack against the SSL VPN web portal.
network
low complexity
citrix CWE-79
6.1
2020-09-18 CVE-2020-8200 Improper Authentication vulnerability in Citrix Storefront Server
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
network
low complexity
citrix CWE-287
6.5