CVE-2022-26151

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:citrix:xenmobile_server:10.13.0:-:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_3:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_4:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_5:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_6:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_7:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:-:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_1:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_2:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_3:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_4:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-20 CWE-77

02 Dec 2022, 22:41

Type Values Removed Values Added
References (MISC) https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe - (MISC) https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe - Third Party Advisory

10 Jun 2022, 18:15

Type Values Removed Values Added
References
  • (MISC) https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe -

20 Apr 2022, 17:18

Type Values Removed Values Added
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 7.2
References (MISC) https://support.citrix.com/article/CTX370551 - (MISC) https://support.citrix.com/article/CTX370551 - Vendor Advisory
References (MISC) https://support.citrix.com/search - (MISC) https://support.citrix.com/search - Vendor Advisory
CPE cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_6:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:-:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_7:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_1:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:-:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_4:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_3:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_5:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_3:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.14.0:rolling_patch_2:*:*:*:*:*:*
cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_4:*:*:*:*:*:*
First Time Citrix xenmobile Server
Citrix

20 Apr 2022, 14:15

Type Values Removed Values Added
Summary Citrix XenMobile Server 10.12 through RP11, 10.13 through RP6, and 10.14 through RP4 allows Command Injection. Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

13 Apr 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-13 00:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-26151

Mitre link : CVE-2022-26151

CVE.ORG link : CVE-2022-26151


JSON object : View

Products Affected

citrix

  • xenmobile_server
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')