CVE-2018-17446SQL Injection in Citrix Netscaler Sd-wan

CWE-89SQL Injection4 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 14

Description

A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDcitrix/netscaler_sd-wan9.3.09.3.6+1
NVDcitrix/sd-wan10.1.0
citrixcitrix/sd-wan

🔴Vulnerability Details

1
GHSA
GHSA-45hj-x6v8-2mjc: A SQL Injection issue was discovered in Citrix SD-WAN 102022-05-14

📋Vendor Advisories

2
Citrix
CVE-2018-17446: A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.2018-10-23
Citrix
Citrix SD-WAN Multiple Security Updates