Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-27506


Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI


Published

2022-04-13T18:15:14.527

Last Modified

2024-11-21T06:55:51.527

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-798
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System citrix sd-wan_110_firmware < 11.4.1 Yes
Hardware citrix sd-wan_110 - No
Operating System citrix sd-wan_210_firmware < 11.4.1 Yes
Hardware citrix sd-wan_210 - No
Operating System citrix sd-wan_400_firmware < 11.4.1 Yes
Hardware citrix sd-wan_400 - No
Operating System citrix sd-wan_410_firmware < 11.4.1 Yes
Hardware citrix sd-wan_410 - No
Operating System citrix sd-wan_1000_firmware < 11.4.1 Yes
Operating System citrix sd-wan_1000_firmware < 11.4.1 Yes
Hardware citrix sd-wan_1000 - No
Operating System citrix sd-wan_2000_firmware < 11.4.1 Yes
Operating System citrix sd-wan_2000_firmware < 11.4.1 Yes
Hardware citrix sd-wan_2000 - No
Operating System citrix sd-wan_2100_firmware < 11.4.1 Yes
Operating System citrix sd-wan_2100_firmware < 11.4.1 Yes
Hardware citrix sd-wan_2100 - No
Operating System citrix sd-wan_4000_firmware < 11.4.1 Yes
Hardware citrix sd-wan_4000 - No
Operating System citrix sd-wan_4100_firmware < 11.4.1 Yes
Hardware citrix sd-wan_4100 - No
Operating System citrix sd-wan_5100_firmware < 11.4.1 Yes
Operating System citrix sd-wan_5100_firmware < 11.4.1 Yes
Hardware citrix sd-wan_5100 - No
Operating System citrix sd-wan_6100_firmware < 11.4.1 Yes
Operating System citrix sd-wan_6100_firmware < 11.4.1 Yes
Hardware citrix sd-wan_6100 - No
Operating System citrix sd-wan_1100_firmware < 11.4.1 Yes
Operating System citrix sd-wan_1100_firmware < 11.4.1 Yes
Hardware citrix sd-wan_1100 - No
Application citrix sd-wan_center_management_console < 11.4.3 Yes
Application citrix sd-wan_orchestrator < 13.2.1 Yes

References