← All CVEs

CVE-2022-27518

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-12-13Remediation due 2023-01-03

Unauthenticated remote arbitrary code execution

9.8
CVSS
6.9%
EPSS (exploit prob.)
94th
EPSS percentile
2022-12-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-664

Affected products

VendorProductAffected versions
citrixapplication_delivery_controller_firmware>= 12.1, < 12.1-55.291
citrixapplication_delivery_controller_firmware>= 12.1, < 12.1-55.291
citrixapplication_delivery_controller_firmware>= 12.1, < 12.1-65.25
citrixapplication_delivery_controller_firmware>= 13.0, < 13.0-58.32
citrixapplication_delivery_controllerall versions
citrixgateway_firmware>= 12.1, < 12.1-65.25
citrixgateway_firmware>= 13.0, < 13.0-58.32
citrixgatewayall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-27518