« Volver al listado

CVE-2016-4810

Estado: ModificadaAlta (7.5)—

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-4810",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-06-01T22:59:05.940",
  "references": [
    {
      "url": "http://support.citrix.com/article/CTX213045",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1036021",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.citrix.com/article/CTX213045",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1036021",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Citrix Studio en versiones anteriores a 7.6.1000, Citrix XenDesktop 7.x en versiones anteriores a 7.6 LTSR Cumulative Update 1 (CU1) y Citrix XenApp 7.5 y 7.6 permiten a atacantes establecer reglas Access Policy en el XenDesktop Delivery Controller a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:48:15.607",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:citrix:xenapp:7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32E4F74A-5F0E-4594-9BB3-8041BEE338C6"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xenapp:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98334CF7-5B0E-42EC-919C-FBDECFD4D810"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22560F24-4D19-41E3-BEFD-4AABB8E289E2"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B75A1E4B-38FB-427D-9293-2113B00CE60D"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FD95B20-D022-4DDA-862A-2744F303D5F5"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12D36FDF-2923-4E9C-8B94-688A56A4E047"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.6:fp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "986EAB37-3DFE-4C89-A066-EE4A46EB4CA2"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.6:fp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58C64C20-B5E7-4698-BD76-86C06648C5D3"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.6:fp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87AA263B-AF98-4BF2-9306-C396389A727C"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xendesktop:7.6:ltsr:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40305BFB-58B4-4A60-BE6C-1074C6D4F205"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}