'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2025-12-24 | |
| Rule Name: | Citrix SD-WAN Center - Local File Inclusion | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Citrix SD-WAN Center is a centralized network management and monitoring platform launched by Citrix (now part of Cloud Software Group), which is used to uniformly configure, manage policies and conduct real-time operation and maintenance for Citrix SD-WAN devices deployed by enterprises. Attackers can construct specially crafted requests to induce the application to read and execute any local file on the server. | |
| Impact: | When the file operation function in the application that does not filter the file path effectively, an attacker can import the path of a file which contains malicious code, causing a file inclusion vulnerability and executing malicious code. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |