CVE-2013-2935
published 2013-09-12CVE-2013-2935: Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.65%
73.8th percentile
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | cloudportal_services_manager | <= 10.0 | — |
| citrix | cloudportal_services_manager | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.2 | 1.1.8-1ubuntu2.2 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjr5-cp28-2vg6: Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10
ghsa_unreviewed·2022-05-17
CVE-2013-2935 [HIGH] GHSA-qjr5-cp28-2vg6: Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
OSV
pam regression
osv·2016-03-16·CVSS 4.3
pam regression
pam regression
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LT
Citrix
CVE-2013-2935: Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a
vendor_citrix·2013-09-12·CVSS 10.0
CVE-2013-2935 [CRITICAL] CVE-2013-2935: Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a
CVE-2013-2935: Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
Citrix
Citrix Security Bulletin CTX137162
vendor_citrix·CVSS 10.0
CVE-2013-2933 [CRITICAL] Citrix Security Bulletin CTX137162
Citrix Security Bulletin CTX137162
CVE References: CVE-2013-2933, CVE-2013-2934, CVE-2013-2935, CVE-2013-2936, CVE-2013-2937, CVE-2013-2938, CVE-2013-2939, CVE-2013-2940, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-12
Published