CVE-2019-18910

MEDIUM

Citrix Receiver - Command Injection

Title source: llm
STIX 2.1

Description

The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://support.hp.com/us-en/document/c06509350
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Mar/40

Scores

CVSS v3 6.8
EPSS 0.0102
EPSS Percentile 77.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (4)
hp/thinpro 6.2
hp/thinpro 6.2.1
hp/thinpro 7.0
hp/thinpro 7.1
Published Nov 22, 2019
Tracked Since Feb 18, 2026