Citrix SD-WAN Security Bulletin for CVE-2022-27505 and CVE-2022-27506

Citrix SD-WAN Security Bulletin for CVE-2022-27505 and CVE-2022-27506

book

Article ID: CTX370550

calendar_today

Updated On:

Description

Vulnerabilities have been discovered in multiple Citrix SD-WAN products. These vulnerabilities, if exploited, could result in the following security issues: 

 

CVE-ID  

Description  

CWE  

Affected Products  

Pre-conditions 

CVE-2022-27505 

Reflected cross site scripting (XSS) 

 

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 

Citrix SD-WAN Standard/Premium Edition Appliance 

Victim user must have a current session on the vulnerable device. 

CVE-2022-27506 

Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI 

CWE-798: Use of Hard-coded Credentials 

Citrix SD-WAN Center Management Console, Citrix SD-WAN Standard/Premium Edition Appliance, and Citrix SD-WAN Orchestrator for On-Premises  

Admin access to SD-WAN CLI 

 

The following supported versions of Citrix SD-WAN are affected by the vulnerabilities 

  • CVE-2022-27505 – High Severity 

Citrix SD-WAN Standard/Premium Edition Appliance before 11.4.3a 

  • CVE-2022-27506 – Low Severity 

Citrix SD-WAN Center Management Console versions before 11.4.3 

Citrix SD-WAN Standard/Premium Edition Appliance versions before 11.4.1 

Citrix SD-WAN Orchestrator for On-Premises versions before 13.2.1 

 


Mitigating Factors

  • CVE-2022-27506: This issue is only exposed to administrators with access to the SD-WAN CLI 


Instructions

  • CVE-2022-27505:  
    Citrix recommends that affected customers upgrade to a fixed version as soon as possible. This issue has been addressed in the following supported Citrix SD-WAN versions: 

Citrix SD-WAN Standard/Premium Edition Appliance versions 11.4.3a and above 

 

  • CVE-2022-27506:  

Citrix recommends that affected customers upgrade to a fixed version as their patching schedule allows. This issue has been addressed in the following supported Citrix SD-WAN versions: 

Citrix SD-WAN Center Management Console versions 11.4.3 and above 

Citrix SD-WAN Standard/Premium Edition Appliance versions 11.4.1 and above 

Citrix SD-WAN Orchestrator for On-Premises versions 13.2.1 and above 


Acknowledgements

Citrix thanks Mattias Dewulf of Spinae for working with us to protect Citrix customers

Additional Information

DateChange
2022-04-12Initial Publication