CVE-2022-27518
Unauthenticated remote arbitrary code execution
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 22.96%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-664, CWE-664
- Published
- 2022-12-13
- Last modified
- 2026-03-13
Affected products
- Citrix Citrix Gateway, Citrix ADC
- Citrix Citrix Gateway, Citrix ADC
- Citrix Citrix Gateway, Citrix ADC
- Citrix Citrix Gateway, Citrix ADC
- Citrix Citrix Gateway, Citrix ADC
- Citrix Citrix Gateway, Citrix ADC
Weakness type
Related vulnerabilities
- CVE-2020-3175 — Cisco MDS 9000 Series Multilayer Switches Denial of Service Vulnerability
- CVE-2022-20856 — Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Mobility Denial of Service Vulnerability
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-20353 — Cisco Secure Email Gateway Security Hardening Release
- CVE-2022-2048 — In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug
- CVE-2022-2191 — In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffer
- CVE-2023-44288 — Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnera
- CVE-2026-20336 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management Vulnerabilities