CVE-2020-6175
https://notcve.org/view.php?id=CVE-2020-6175
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. Citrix SD-WAN versiones 10.2.x anteriores a 10.2.6 y versiones 11.0.x anteriores a 11.0.3, presenta una Falta de Comprobación del Certificado SSL. • https://support.citrix.com/article/CTX263526 https://support.citrix.com/search • CWE-295: Improper Certificate Validation •
CVE-2019-11345
https://notcve.org/view.php?id=CVE-2019-11345
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. Citrix SD-WAN Center versiones 10.2.x anteriores a la versión 10.2.1 y NetScaler SD-WAN Center versiones 10.0.x anteriores a la versión 10.0.7, permiten un ataque de tipo XSS. • https://support.citrix.com/article/CTX247737 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-3620
https://notcve.org/view.php?id=CVE-2013-3620
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312. Credenciales WSMan embebidas en Intelligent Platform Management Interface (IPMI) con firmware para tarjetas madres generación X9 Supermicro versiones anteriores a la versión 3.15 (SMT_X9_315) y firmware para tarjetas madres generación X8 Supermicro versiones anteriores a la versión SMT X8 312. • http://support.citrix.com/article/CTX216642 https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilities https://exchange.xforce.ibmcloud.com/vulnerabilities/89045 https://support.citrix.com/article/CTX216642 https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf • CWE-522: Insufficiently Protected Credentials •
CVE-2013-3619 – Supermicro Onboard IPMI Static SSL Certificate Scanner
https://notcve.org/view.php?id=CVE-2013-3619
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon. Intelligent Platform Management Interface (IPMI) con firmware para las tarjetas madres generación X9 Supermicro versiones anteriores a SMT_X9_317 y el firmware para las tarjetas madres generación X8 Supermicro versiones anteriores a la verisón SMT X8 312, contienen claves de cifrado privadas embebidas para la (1) interfaz SSL del servidor web Lighttpd y el (2) demonio Dropbear SSH. • http://support.citrix.com/article/CTX216642 https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilities https://exchange.xforce.ibmcloud.com/vulnerabilities/89044 https://support.citrix.com/article/CTX216642 https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf • CWE-798: Use of Hard-coded Credentials •
CVE-2019-12985
https://notcve.org/view.php?id=CVE-2019-12985
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). SD-WAN versiones 10.2.x anteriores a 10.2.3 de Citrix y SD-WAN versiones 10.0.x anteriores a 10.0.8 de NetScaler, presentan una Comprobación de Entrada Inapropiada (problema 1 de 6). • http://www.securityfocus.com/bid/109133 https://support.citrix.com/article/CTX251987 https://www.tenable.com/security/research/tra-2019-31 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •