CVE-2022-26151Command Injection in Citrix Xenmobile Server

Severity
7.2HIGHNVD
EPSS
2.5%
top 14.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateApr 14

Description

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

NVDcitrix/xenmobile_server10.13.0, 10.14.0+1

🔴Vulnerability Details

1
GHSA
GHSA-rgf2-86fc-62hw: Citrix XenMobile Server 102022-04-14

📋Vendor Advisories

1
Citrix
CVE-2022-26151: Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.2022-04-13