ID

VAR-202211-0767


CVE

CVE-2022-27510


TITLE

of Citrix Systems  Citrix Gateway  and  Citrix Application Delivery Controller  Authentication vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2022-020612

DESCRIPTION

Unauthorized access to Gateway user capabilities . of Citrix Systems Citrix Gateway and Citrix Application Delivery Controller An authentication vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2022-27510 // JVNDB: JVNDB-2022-020612 // VULHUB: VHN-418144

AFFECTED PRODUCTS

vendor:citrixmodel:application delivery controllerscope:ltversion:12.1-65.21

Trust: 1.0

vendor:citrixmodel:gatewayscope:gteversion:12.1

Trust: 1.0

vendor:citrixmodel:gatewayscope:gteversion:13.1

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:gteversion:13.0

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:13.1-33.47

Trust: 1.0

vendor:citrixmodel:gatewayscope:gteversion:13.0

Trust: 1.0

vendor:citrixmodel:gatewayscope:ltversion:13.1-33.41

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:gteversion:12.1

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:gteversion:13.1

Trust: 1.0

vendor:citrixmodel:gatewayscope:ltversion:13.0-88.12

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:13.0-88.12

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:12.1-55.289

Trust: 1.0

vendor:citrixmodel:gatewayscope:ltversion:12.1-65.21

Trust: 1.0

vendor:シトリックス システムズmodel:citrix gatewayscope: - version: -

Trust: 0.8

vendor:シトリックス システムズmodel:citrix application delivery controllerscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-020612 // NVD: CVE-2022-27510

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-27510
value: CRITICAL

Trust: 1.0

secure@citrix.com: CVE-2022-27510
value: CRITICAL

Trust: 1.0

NVD: CVE-2022-27510
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202211-2372
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-27510
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2022-27510
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-020612 // CNNVD: CNNVD-202211-2372 // NVD: CVE-2022-27510 // NVD: CVE-2022-27510

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:CWE-288

Trust: 1.0

problemtype:Inappropriate authentication (CWE-287) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-418144 // JVNDB: JVNDB-2022-020612 // NVD: CVE-2022-27510

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202211-2372

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202211-2372

PATCH

title:Citrix Gateway and Citrix ADC Remediation measures for authorization problem vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=213780

Trust: 0.6

sources: CNNVD: CNNVD-202211-2372

EXTERNAL IDS

db:NVDid:CVE-2022-27510

Trust: 3.3

db:JVNDBid:JVNDB-2022-020612

Trust: 0.8

db:CNNVDid:CNNVD-202211-2372

Trust: 0.6

db:VULHUBid:VHN-418144

Trust: 0.1

sources: VULHUB: VHN-418144 // JVNDB: JVNDB-2022-020612 // CNNVD: CNNVD-202211-2372 // NVD: CVE-2022-27510

REFERENCES

url:https://support.citrix.com/article/ctx463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-27510

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-27510/

Trust: 0.6

sources: VULHUB: VHN-418144 // JVNDB: JVNDB-2022-020612 // CNNVD: CNNVD-202211-2372 // NVD: CVE-2022-27510

SOURCES

db:VULHUBid:VHN-418144
db:JVNDBid:JVNDB-2022-020612
db:CNNVDid:CNNVD-202211-2372
db:NVDid:CVE-2022-27510

LAST UPDATE DATE

2024-08-14T14:49:30.708000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-418144date:2022-11-09T00:00:00
db:JVNDBid:JVNDB-2022-020612date:2023-11-02T08:06:00
db:CNNVDid:CNNVD-202211-2372date:2022-11-10T00:00:00
db:NVDid:CVE-2022-27510date:2023-10-18T17:15:08.340

SOURCES RELEASE DATE

db:VULHUBid:VHN-418144date:2022-11-08T00:00:00
db:JVNDBid:JVNDB-2022-020612date:2023-11-02T00:00:00
db:CNNVDid:CNNVD-202211-2372date:2022-11-08T00:00:00
db:NVDid:CVE-2022-27510date:2022-11-08T22:15:13.020