Show filters
370 Total Results
Displaying 31-40 of 370
Sort by:
Attacker Value
Unknown

CVE-2024-3661

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Attacker Value
Unknown

CVE-2024-2049

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
0
Attacker Value
Unknown

CVE-2023-6184

Disclosure Date: January 18, 2024 (last updated January 25, 2024)
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Attacker Value
Unknown

CVE-2023-4967

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Attacker Value
Unknown

CVE-2023-3467

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
Privilege Escalation to root administrator (nsroot)
Attacker Value
Unknown

CVE-2023-3466

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
Reflected Cross-Site Scripting (XSS)
Attacker Value
Unknown

CVE-2023-24492

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
Attacker Value
Unknown

CVE-2023-24491

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
Attacker Value
Unknown

CVE-2023-24490

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Users with only access to launch VDA applications can launch an unauthorized desktop
Attacker Value
Unknown

CVE-2023-24489

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.