CVE-2022-27506

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
13/04/2022
Last modified:
23/04/2022

Description

Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:citrix:sd-wan_110_firmware:*:*:*:*:standard:*:*:* 11.4.1 (excluding)
cpe:2.3:h:citrix:sd-wan_110:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:sd-wan_210_firmware:*:*:*:*:standard:*:*:* 11.4.1 (excluding)
cpe:2.3:h:citrix:sd-wan_210:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:sd-wan_400_firmware:*:*:*:*:standard:*:*:* 11.4.1 (excluding)
cpe:2.3:h:citrix:sd-wan_400:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:sd-wan_410_firmware:*:*:*:*:standard:*:*:* 11.4.1 (excluding)
cpe:2.3:h:citrix:sd-wan_410:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:premium:*:*:* 11.4.1 (excluding)
cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:standard:*:*:* 11.4.1 (excluding)
cpe:2.3:h:citrix:sd-wan_1000:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:premium:*:*:* 11.4.1 (excluding)
cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:standard:*:*:* 11.4.1 (excluding)
cpe:2.3:h:citrix:sd-wan_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:premium:*:*:* 11.4.1 (excluding)


References to Advisories, Solutions, and Tools