Citrix SD-WAN设备多个漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Synopsis Multiple vulnerabilities were discovered in the Citrix SD-WAN appliance. By exploiting the vulnerabilities in combination, a remote, unauthenticated attacker can gain root access. #### Unauthenticated SQL Injection /sdwan/nitro/v1/config/get_package_file The cgi-bin/sdwanrestapi/getpackagefile.cgi Perl script contains a SQL injection vulnerability that can be exploited by a remote, unauthenticated attacker. Input validation is not applied before incorporating user input in a SQL query. By exploiting this vulnerability with a crafted HTTP request, an attacker is able to write to (and create) files in locations writable by the 'mysql' user. For instance, a file can be created in the /tmp directory. A SQL injection payload can be constructed in such a way that the attacker is able to completely bypass the authentication mechanism by writing a token file to the /tmp directory. The SQL injection vulnerability can be triggered by crafting the HTTP POST request such that: -...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息