Citrix ADC
cpe:2.3:h:citrix:application_delivery_controller:*:*:*:*:*:*:*, +7 more
This vulnerability is being actively exploited in the wild.
A vulnerability allowing unauthenticated remote arbitrary code execution has been identified in Citrix Application Delivery Controller (ADC) and Citrix Gateway. This issue arises in configurations using SAML Service Provider or Identity Provider, where an authentication bypass allows attackers to execute code with administrative privileges.
Exploitation of this vulnerability allows for unauthenticated remote code execution with administrative rights on the affected system.
Users are advised to apply updates according to Citrix's vendor instructions. Details can be found in the Citrix ADC and Citrix Gateway Security Bulletin for CVE-2022-27518.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.