Vulnerabilidades en Citrix

40 resultados
Análisis Vexday

Citrix apresenta 40 vulnerabilidades registradas com 5 já exploradas ativamente em campo, incluindo 6 críticas. A fraqueza dominante (CWE-269: Improper Access Control) sugere problemas estruturais de autenticação e autorização. Com apenas 2 vulnerabilidades publicadas nos últimos 90 dias, o risco atual é mais relacionado ao legado não patchado do que a ameaças emergentes, mas a taxa de exploração ativa justifica prioridade imediata nas correções conhecidas.

CVE-2023-4966CRITICALUnauthenticated sensitive information disclosureEPSS 100.0%KEVCVE-2023-3519CRITICALUnauthenticated remote code executionEPSS 99.7%KEVCVE-2023-24489CRITICALA vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthentEPSS 94.7%KEVCVE-2023-24488MEDIUMCross site scriptingEPSS 80.9%CVE-2022-27511Corruption of the system by a remote, unauthenticated user potentially leading to the reset of the administrator passwordEPSS 11.8%CVE-2022-27518CRITICALUnauthenticated remote arbitrary code executionEPSS 6.9%KEVCVE-2023-3466HIGHReflected Cross-Site Scripting (XSS) EPSS 2.8%CVE-2023-3467HIGHPrivilege Escalation to root administrator (nsroot) EPSS 1.6%CVE-2024-8068MEDIUMPrivilege escalation to NetworkService Account accessEPSS 1.4%KEVCVE-2022-27510CRITICALUnauthorized access to Gateway user capabilities EPSS 1.2%CVE-2023-24487MEDIUMArbitrary file readEPSS 1.1%CVE-2022-27512Temporary disruption of the ADM license serviceEPSS 0.9%CVE-2023-24492CRITICAL A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely EPSS 0.9%CVE-2022-27516MEDIUMUser login brute force protection functionality bypass EPSS 0.6%CVE-2022-27503Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9EPSS 0.5%CVE-2024-6148MEDIUMBypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5EPSS 0.4%CVE-2024-6286HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.4%CVE-2024-2049MEDIUMServer-Side Request Forgery (SSRF)EPSS 0.4%CVE-2023-24490MEDIUMUsers with only access to launch VDA applications can launch an unauthorized desktopEPSS 0.3%CVE-2022-27513HIGHRemote desktop takeover via phishingEPSS 0.3%