CVE-2019-17366
published 2019-10-09CVE-2019-17366: Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
PriorityP346high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.25%
65.9th percentile
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | application_delivery_management | — | — |
| citrix | application_delivery_management | — | — |
| citrix | citrix_adm | — | — |
| citrix | citrix_application_delivery_management | — | — |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2019-17366: Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
vendor_citrix·2019-10-09·CVSS 8.8
CVE-2019-17366 [HIGH] CVE-2019-17366: Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
CVE-2019-17366: Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
Citrix
CVE-2019-17366 - Citrix Application Delivery Management (ADM) Console Security Update
vendor_citrix·CVSS 8.8
CVE-2019-17366 [HIGH] CVE-2019-17366 - Citrix Application Delivery Management (ADM) Console Security Update
CVE-2019-17366 - Citrix Application Delivery Management (ADM) Console Security Update
of Problem An authorisation bypass vulnerability was discovered in the Citrix Application Delivery Management (ADM) server. The vulnerability allows a Citrix ADM user with read-only privilege to access a managed instances with admin level permissions. The following deployment scenarios are affected: 1. A Citrix Application Delivery Management server on-premises 2. A Citrix Application Delivery Management on Cloud, deployed on-premises or customer-managed cloud datacenters. This vulnerability has been assigned the following CVE number: • CVE-2019-17366: Improper Access Control in Citrix Application Delivery Management Server. This vulnerability affects the following product versions: · Citrix Application
GHSA
GHSA-fm4g-2r58-3xc3: Citrix Application Delivery Management (ADM) 12
ghsa_unreviewed·2022-05-24
CVE-2019-17366 [HIGH] GHSA-fm4g-2r58-3xc3: Citrix Application Delivery Management (ADM) 12
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-09
Published