CRITICAL

CVE-2022-27518

Citrix Application Delivery Controller Firmware 2022-12-13 CVSS v3.1
CVSS
9.8
KEV

Description

Unauthenticated remote arbitrary code execution

Summary dbcve.org

This is a critical unauthenticated remote arbitrary code execution vulnerability with a CVSS score of 9.8, indicating severe risk. An attacker can exploit this flaw remotely without any credentials to execute arbitrary code on the affected system, potentially leading to complete system compromise.

Mitigation

Apply vendor-provided patches or updates immediately, as this is an unauthenticated RCE that can be exploited remotely. Prioritize internet-facing systems and implement network segmentation as a compensating control until patching is complete.

Weakness (CWE)

CWE-664

EPSS Score

6.68%
Probability of exploitation in next 30 days
93.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE