CVE-2020-6175
https://notcve.org/view.php?id=CVE-2020-6175
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. Citrix SD-WAN versiones 10.2.x anteriores a 10.2.6 y versiones 11.0.x anteriores a 11.0.3, presenta una Falta de Comprobación del Certificado SSL. • https://support.citrix.com/article/CTX263526 https://support.citrix.com/search • CWE-295: Improper Certificate Validation •
CVE-2019-11345
https://notcve.org/view.php?id=CVE-2019-11345
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. Citrix SD-WAN Center versiones 10.2.x anteriores a la versión 10.2.1 y NetScaler SD-WAN Center versiones 10.0.x anteriores a la versión 10.0.7, permiten un ataque de tipo XSS. • https://support.citrix.com/article/CTX247737 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-10112 – Citrix Gateway 11.1 / 12.0 / 12.1 Cache Poisoning
https://notcve.org/view.php?id=CVE-2020-10112
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default ** EN DISPUTA ** Citrix Gateway 11.1, 12.0 y 12.1 permite el envenenamiento de caché. • http://packetstormsecurity.com/files/156660/Citrix-Gateway-11.1-12.0-12.1-Cache-Poisoning.html http://seclists.org/fulldisclosure/2020/Mar/8 https://support.citrix.com/search • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •
CVE-2020-10111 – Citrix Gateway 11.1 / 12.0 / 12.1 Cache Bypass
https://notcve.org/view.php?id=CVE-2020-10111
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization ** EN DISPUTA ** Citrix Gateway 11.1, 12.0 y 12.1 tiene una interpretación inconsistente de las solicitudes HTTP. NOTA: Citrix cuestiona el comportamiento informado como un problema de seguridad. Citrix ADC solo almacena en caché el tráfico HTTP / 1.1 para la optimización del rendimiento. • http://packetstormsecurity.com/files/156661/Citrix-Gateway-11.1-12.0-12.1-Cache-Bypass.html http://seclists.org/fulldisclosure/2020/Mar/11 https://support.citrix.com/search • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •
CVE-2020-10110 – Citrix Gateway 11.1 / 12.0 / 12.1 Information Disclosure
https://notcve.org/view.php?id=CVE-2020-10110
Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request or a response. The "Age" header provides the age of the cached response in seconds. • http://packetstormsecurity.com/files/156656/Citrix-Gateway-11.1-12.0-12.1-Information-Disclosure.html https://seclists.org/fulldisclosure/2020/Mar/7 https://support.citrix.com/search •