Number: AV22-198
Date: 12 April 2022
On 12 April 2022 Citrix published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:
- Citrix SD-WAN Center Management Console – versions prior to 11.4.3
- Citrix SD-WAN Standard/Premium Edition Appliance – versions prior to 11.4.1
- Citrix SD-WAN Orchestrator for On-Premises – versions prior to 13.2.1
Exploitation of these vulnerabilities could allow cross-site scripting and unauthorized access.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Citrix SD-WAN Security Bulletin for CVE-2022-27505 and CVE-2022-27506