NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。
Assigner(CNA/発行元):[email protected] この条件を外す
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2022-26355 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS adminis | 4.4 | 0.03% | 2022-03-10 | 2024-11-21 |
| CVE-2022-27503 | Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 | 6.1 | 0.39% | 2022-04-13 | 2024-11-21 |
| CVE-2022-27505 | Reflected cross site scripting (XSS) | 6.1 | 0.39% | 2022-04-13 | 2024-11-21 |
| CVE-2022-27506 | Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | 2.7 | 0.17% | 2022-04-13 | 2024-11-21 |
| CVE-2022-27511 | Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted. | 8.1 | 22.37% | 2022-06-16 | 2024-11-21 |
| CVE-2022-27512 | Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | 5.3 | 0.88% | 2022-06-16 | 2024-11-21 |
| CVE-2022-27509 | Unauthenticated redirection to a malicious website | 6.1 | 0.33% | 2022-07-28 | 2024-11-21 |
| CVE-2022-27510 | Unauthorized access to Gateway user capabilities | 9.8 | 1.18% | 2022-11-08 | 2024-11-21 |
| CVE-2022-27513 | Remote desktop takeover via phishing | 8.3 | 0.41% | 2022-11-08 | 2024-11-21 |
| CVE-2022-27516 | User login brute force protection functionality bypass | 5.3 | 0.09% | 2022-11-08 | 2024-11-21 |
| CVE-2022-27518 KEV | Unauthenticated remote arbitrary code execution | 9.8 | 27.69% | 2022-12-13 | 2026-02-25 |
| CVE-2022-27507 | Authenticated denial of service | 6.5 | 0.83% | 2023-01-26 | 2025-04-01 |
| CVE-2022-27508 | Unauthenticated denial of service | 7.5 | 0.82% | 2023-01-26 | 2025-04-01 |
| CVE-2023-24483 | A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | 7.8 | 0.14% | 2023-02-16 | 2025-03-18 |
| CVE-2023-24484 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. | 5.5 | 0.10% | 2023-02-16 | 2025-03-18 |
| CVE-2023-24485 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | 7.8 | 0.14% | 2023-02-16 | 2025-03-19 |
| CVE-2023-24486 | A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | 5.5 | 0.06% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24487 | Arbitrary file read in Citrix ADC and Citrix Gateway | 6.3 | 31.96% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24488 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | 6.1 | 91.36% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24489 KEV | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | 9.8 | 94.39% | 2023-07-10 | 2026-02-26 |