CVE-2021-44520 Information
Jun 07, 2022
cve
Description
In Citrix XenMobile Server through 10.12 RP9 there is an Authenticated Command Injection vulnerability leading to remote code execution with root privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://gist.github.com/tree-chtsec/766f81e22ae383987d75eedb3b23b709 https://docs.citrix.com/en-us/xenmobile/server/document-history.html https://support.citrix.com/article/CTX370551
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: