5
CVSSv2

CVE-2015-2682

Published: 26/03/2015 Updated: 05/02/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Citrix Command Center prior to 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote malicious users to obtain credentials via a direct request to conf/securitydbData.xml.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citrix command center 5.2

citrix command center 5.1

Exploits

Abstract It was discovered that Citrix Command Center stores configuration files containing credentials of managed devices within a folder accessible through the web server Unauthenticated attackers can download any configuration file stored in this folder, decode passwords stored in these files, and gain privileged access to devices managed by ...