Vulnerabilities > Citrix > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-02 CVE-2013-3620 Insufficiently Protected Credentials vulnerability in multiple products
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
network
low complexity
supermicro citrix CWE-522
5.0
2020-01-02 CVE-2013-3619 Use of Hard-coded Credentials vulnerability in multiple products
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
4.3
2019-10-09 CVE-2019-17366 Unspecified vulnerability in Citrix Application Delivery Management 12.1/13.0
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
network
low complexity
citrix
6.5
2019-08-29 CVE-2019-13608 XXE vulnerability in Citrix Storefront Server
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
network
low complexity
citrix CWE-611
5.0
2019-07-11 CVE-2014-3798 Improper Input Validation vulnerability in Citrix Xenserver
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
low complexity
citrix CWE-20
6.1
2019-06-05 CVE-2018-18571 Improper Authentication vulnerability in Citrix Xenmobile Server 10.8.0/10.9.0
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3.
network
low complexity
citrix CWE-287
6.4
2019-05-22 CVE-2019-12044 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix products
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.
network
low complexity
citrix CWE-119
5.0
2019-05-13 CVE-2019-7218 Improper Authentication vulnerability in Citrix Sharefile
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication.
network
citrix CWE-287
4.3
2019-05-13 CVE-2019-7217 Information Exposure Through Discrepancy vulnerability in Citrix Sharefile
Citrix ShareFile before 19.12 allows User Enumeration.
network
low complexity
citrix CWE-203
5.0
2019-05-08 CVE-2019-11550 Improper Certificate Validation vulnerability in Citrix Netscaler Sd-Wan and Sd-Wan
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
network
citrix CWE-295
4.3