CVE-2022-27506
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: NVD
Description
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
Affected (20)
Products: Citrix: Sd Wan 110 Firmware, Sd Wan 210 Firmware, Sd Wan 400 Firmware, Sd Wan 410 Firmware, Sd Wan 1000 Firmware, Sd Wan 2000 Firmware, Sd Wan 2100 Firmware, Sd Wan 4000 Firmware, Sd Wan 4100 Firmware, Sd Wan 5100 Firmware, Sd Wan 6100 Firmware, Sd Wan 1100 Firmware, Sd Wan Center Management Console, Sd Wan Orchestrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 110 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 210 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 400 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 410 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 1000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 2000 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 2100 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 4000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 4100 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 5100 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 6100 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.1 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 1100 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.4.3 | |
| Before 13.2.1 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.