Citrix
Citrix Sd-wan: vulnerabilidades y CVE
Citrix Sd-wan tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas10
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-12991 | Alta (8.8) | 74% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). |
| CVE-2019-12989 | Crítica (9.8) | 95% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-22956 | Alta (7.5) | 0.92% | — | 7 dic 2021 | An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a… |
| CVE-2020-8273 | Alta (8.8) | 2.4% | — | 16 nov 2020 | Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8. |
| CVE-2020-8272 | Alta (7.5) | 1.5% | — | 16 nov 2020 | Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 |
| CVE-2020-8271 | Crítica (9.8) | 11% | — | 16 nov 2020 | Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 |
| CVE-2019-12992 | Alta (8.8) | 49% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). |
| CVE-2019-12991 | Alta (8.8) | 74% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). |
| CVE-2019-12990 | Crítica (9.8) | 39% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. |
| CVE-2019-12989 | Crítica (9.8) | 95% | ⚠ Explotación activa | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
| CVE-2019-12988 | Crítica (9.8) | 43% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). |
| CVE-2019-12987 | Crítica (9.8) | 43% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). |
| CVE-2019-12986 | Crítica (9.8) | 40% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). |
| CVE-2019-12985 | Crítica (9.8) | 40% | — | 16 jul 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). |
| CVE-2019-11550 | Media (5.9) | 0.58% | — | 8 may 2019 | Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. |
| CVE-2018-17448 | Crítica (9.8) | 2.2% | — | 23 oct 2018 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17447 | Alta (7.5) | 1.9% | — | 23 oct 2018 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17446 | Crítica (9.8) | 2.0% | — | 23 oct 2018 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17445 | Crítica (9.8) | 11% | — | 23 oct 2018 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
| CVE-2018-17444 | Alta (7.5) | 3.6% | — | 23 oct 2018 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
📰 Noticias relacionadas
Otros productos de Citrix
Xenserver · 55Netscaler Gateway · 45Netscaler Application Delivery Controller · 39Netscaler Gateway Firmware · 31Application Delivery Controller Firmware · 30Netscaler Application Delivery Controller Firmware · 29Xenmobile Server · 22Gateway · 19Netscaler Sd-wan · 16Gateway Firmware · 15Workspace · 14Access Gateway · 14