Citrix Netscaler Sdx Firmware vulnerabilities
4 known vulnerabilities affecting citrix/netscaler_sdx_firmware.
Total CVEs
4
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2013-3619HIGHCVSS 8.1v102020-01-02
CVE-2013-3619 [HIGH] CWE-798 CVE-2013-3619: Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherbo
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
nvd
CVE-2013-3620HIGHCVSS 7.5v102020-01-02
CVE-2013-3620 [HIGH] CWE-522 CVE-2013-3620: Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Su
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
nvd
CVE-2014-7169CRITICALCVSS 9.8KEVPoCfixed in 9.3.67.5r1≥ 10, < 10.1.129.11r1+1 more2014-09-25
CVE-2014-7169 [CRITICAL] CVE-2014-7169: GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definiti
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgi
nvd
CVE-2014-6271CRITICALCVSS 9.8KEVPoCfixed in 9.3.67.5r1≥ 10, < 10.1.129.11r1+1 more2014-09-24
CVE-2014-6271 [CRITICAL] CWE-78 CVE-2014-6271: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environm
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts execute
nvd