Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Virtual Apps And Desktops HIGH 8.8
CVE-2020-8270

An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 …

Fix: after 2006
Fix from $1,950 2020-11-16
Sd Wan HIGH 8.8
CVE-2020-8273

Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.

Fix: 10.2.8 / 11.1.2b+
Fix from $1,950 2020-11-16
Sd Wan HIGH 7.5
CVE-2020-8272

Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

Fix: 10.2.8 / 11.1.2b+
Fix from $1,950 2020-11-16
Application Delivery Controller Firmware HIGH 8.8
CVE-2020-8247

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18…

Fix: 10.2.7b / 11.0.3f+
Fix from $1,950 2020-09-18
Application Delivery Controller Firmware HIGH 7.5
CVE-2020-8246

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18…

Fix: 10.2.7b / 11.0.3f+
Fix from $1,950 2020-09-18
Xenmobile Server HIGH 7.5
CVE-2020-8253

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before R…

Fix: after 10.8.0
Fix from $1,950 2020-09-18
Application Delivery Controller Firmware MEDIUM 6.1
CVE-2020-8245

Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix AD…

Fix: 11.1-65.12 / 12.1-58.15+
Fix from $1,600 2020-09-18
Storefront Server MEDIUM 6.5
CVE-2020-8200

Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory doma…

Fix: 3.0.8001 / 3.12.5001+
Fix from $1,600 2020-09-18
Xenmobile Server CRITICAL 9.8
CVE-2020-8211

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 an…

Fix: after 10.8.0
Fix from $2,300 2020-08-17
Xenmobile Server CRITICAL 9.8
CVE-2020-8212

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and …

Fix: after 10.9.0
Fix from $2,300 2020-08-17
Xenmobile Server HIGH 7.5
CVE-2020-8209EPSS 49%

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before R…

Fix: after 10.8.0
Fix from $1,950 2020-08-17
Xenmobile Server HIGH 7.5
CVE-2020-8210

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.…

Fix: after 10.8.0
Fix from $1,950 2020-08-17
Xenmobile Server MEDIUM 6.1
CVE-2020-8208

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before…

Fix: after 10.8.0
Fix from $1,600 2020-08-17
Workspace HIGH 8.8
CVE-2020-8207

Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd…

Mitigation only
Fix from $1,950 2020-07-24
Application Delivery Controller Firmware HIGH 8.8
CVE-2020-8197

Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 all…

Fix: 10.5-70.18 / 11.1-64.14+
Fix from $1,950 2020-07-10
Gateway Plug In For Linux HIGH 7.8
CVE-2020-8199

Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.

Fix: 1.0.0.137+
Fix from $1,950 2020-07-10
Application Delivery Controller Firmware HIGH 7.5
CVE-2020-8190

Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows priv…

Fix: 10.5-70.18 / 11.1-64.14+
Fix from $1,950 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8194EPSS 11%

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8195 KEVEPSS 33%

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S…

Fix: 1.0.0.137 / 10.2.7+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.1
CVE-2020-8191EPSS 26%

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.1
CVE-2020-8198

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware HIGH 7.5
CVE-2020-8187

Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial …

Fix: 11.1-63.9 / 12.0-62.10+
Fix from $1,950 2020-07-10
Xenapp MEDIUM 5.3
CVE-2020-13998

Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA er…

Mitigation only
Fix from $1,600 2020-06-11
Workspace App HIGH 7.8
CVE-2020-13884

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges d…

Fix: 2006.1+
Fix from $1,950 2020-06-08
Workspace App HIGH 7.8
CVE-2020-13885

Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the app…

Fix: 2006.1+
Fix from $1,950 2020-06-08
Sharefile Storagezones Controller HIGH 7.5
CVE-2020-8982EPSS 27%

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the mo…

Fix: after 5.5.0
Fix from $1,950 2020-05-07
Sharefile Storagezones Controller HIGH 7.5
CVE-2020-8983

An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.…

Fix: after 5.5.0
Fix from $1,950 2020-05-07
Sharefile Storagezones Controller HIGH 7.5
CVE-2020-7473EPSS 14%

In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of …

Fix: after 5.5.0
Fix from $1,950 2020-05-07
Citrix Sd Wan Center MEDIUM 5.9
CVE-2020-6175

Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.

Fix: 10.2.6 / 11.0.3+
Fix from $1,600 2020-03-16