Citrix
Citrix Netscaler Sd-wan: vulnerabilidades y CVE
Citrix Netscaler Sd-wan tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas10
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-12991 | Alta (8.8) | 74% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). |
| CVE-2019-12989 | Crítica (9.8) | 95% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
| CVE-2017-6316 | Crítica (9.8) | 73% | ⚠ Explotación activa | 20 jul 2017 | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-12992 | Alta (8.8) | 49% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). |
| CVE-2019-12991 | Alta (8.8) | 74% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). |
| CVE-2019-12990 | Crítica (9.8) | 39% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. |
| CVE-2019-12989 | Crítica (9.8) | 95% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
| CVE-2019-12988 | Crítica (9.8) | 43% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). |
| CVE-2019-12987 | Crítica (9.8) | 43% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). |
| CVE-2019-12986 | Crítica (9.8) | 40% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). |
| CVE-2019-12985 | Crítica (9.8) | 40% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). |
| CVE-2019-11550 | Media (5.9) | 0.58% | — | 8 may 2019 | Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. |
| CVE-2018-17448 | Crítica (9.8) | 2.2% | — | 23 oct 2018 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17447 | Alta (7.5) | 1.9% | — | 23 oct 2018 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17446 | Crítica (9.8) | 2.0% | — | 23 oct 2018 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17445 | Crítica (9.8) | 11% | — | 23 oct 2018 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17444 | Alta (7.5) | 3.6% | — | 23 oct 2018 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-5314 | Alta (7.5) | 2.8% | — | 1 mar 2018 | Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with… |
| CVE-2017-6316 | Crítica (9.8) | 73% | ⚠ Explotación activa | 20 jul 2017 | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
📰 Noticias relacionadas
Otros productos de Citrix
Xenserver · 55Netscaler Gateway · 45Netscaler Application Delivery Controller · 39Netscaler Gateway Firmware · 31Application Delivery Controller Firmware · 30Netscaler Application Delivery Controller Firmware · 29Xenmobile Server · 22Gateway · 19Sd-wan · 18Gateway Firmware · 15Workspace · 14Access Gateway · 14