VulnerabilityModified
CVE-2015-2682
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.
MEDIUM 5.0EPSS 10.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 10.71% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-17
- Affected
- citrix/command center
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/130928/Citrix-Command-Center-Configuration-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Mar/126Mailing List, Third Party Advisory
- http://support.citrix.com/article/CTX200584Vendor Advisory
- http://www.securityfocus.com/bid/73309Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031993Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/36441/Third Party Advisory, VDB Entry
- https://www.securify.nl/advisory/SFY20140802/citrix_command_center_allows_downloading_of_configuration_files.htmlExploit
- http://packetstormsecurity.com/files/130928/Citrix-Command-Center-Configuration-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Mar/126Mailing List, Third Party Advisory
- http://support.citrix.com/article/CTX200584Vendor Advisory
- http://www.securityfocus.com/bid/73309Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031993Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/36441/Third Party Advisory, VDB Entry
- https://www.securify.nl/advisory/SFY20140802/citrix_command_center_allows_downloading_of_configuration_files.htmlExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.