CVE-2022-27506 is a hard-coded credentials vulnerability affecting Citrix SD-WAN products, allowing authenticated administrators to access the shell via the command-line interface. This vulnerability has a low CVSS score of 2.7, indicating a low severity due to the requirement of high privileges (PR:H) and limited impact (C:L, I:N, A:N). There is no evidence of active exploitation, and no public exploit code is available, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4.1CPE matchmatch criteria | cpe:2.3:o:citrix:sd-wan_110_firmware:*:*:*:*:standard:*:*:* | ||
< 11.4.1CPE matchmatch criteria | cpe:2.3:o:citrix:sd-wan_210_firmware:*:*:*:*:standard:*:*:* | ||
< 11.4.1CPE matchmatch criteria | cpe:2.3:o:citrix:sd-wan_400_firmware:*:*:*:*:standard:*:*:* | ||
< 11.4.1CPE matchmatch criteria | cpe:2.3:o:citrix:sd-wan_410_firmware:*:*:*:*:standard:*:*:* | ||
< 11.4.1CPE matchmatch criteria | cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:premium:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.