Citrix ADC

2021 年 4 月的签名更新

为 2021-04-22 周确定的漏洞生成了新的签名规则。您可以下载并配置这些签名规则,以保护您的设备免受安全漏洞攻击。

签名版本

签名与以下软件版本的 Citrix Application Delivery Controller (ADC) (ADC) 11.1、12.0、12.1、13.0 和 13.1 兼容。

Citrix ADC 12.0 版本已达到生命周期终止 (EOL)。有关详细信息,请参阅 版本生命周期 页面。

注意:

启用发布主体和响应主体签名规则可能会影响 Citrix ADC CPU。

常见漏洞条目 (CVE) 见解

以下是签名规则、CVE ID 及其描述的列表。

签名规则 CVE ID 说明
999275 CVE-2021-3378 WEB-MISC FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload Vulnerability (CVE-2021-3378)
999276 CVE-2021-28925 WEB-MISC Nagios Network Analyzer Prior to 2.4.3 - SQL Injection Vulnerability (CVE-2021-28925)
999277 CVE-2021-28924 WEB-MISC Nagios Network Analyzer Prior to 2.4.3 - XSS Vulnerability (CVE-2021-28924)
999278 CVE-2021-27927 WEB-MISC Zabbix - CSRF Vulnerability Via action=authentication.update (CVE-2021-27927)
999279 CVE-2021-26295 WEB-MISC Apache OFBiz 17.12.06 - Unauthenticated Arbitrary Deserialization Vulnerability (CVE-2021-26295)
999280 CVE-2021-25770 WEB-MISC JetBrains YouTrack Prior to 2020.5.3123 - Server-Side Template Injection Vulnerability (CVE-2021-25770)
999281 CVE-2021-25283 WEB-MISC SaltStack Prior to 3002.5 - Remote Code Execution Vulnerability (CVE-2021-25283)
999282 CVE-2021-25283 WEB-MISC SaltStack Prior to 3002.5 - Remote Code Execution Vulnerability Via JSON Object (CVE-2021-25283)
999283 CVE-2021-24218 WEB-WORDPRESS Facebook for WordPress Plugin Prior to 3.0.4 - Stored Cross-Site Scripting Vulnerability (CVE-2021-24218)
999284 CVE-2021-24217 WEB-WORDPRESS Facebook for WordPress Plugin Prior to 3.0.2 - PHP Object Injection Vulnerability (CVE-2021-24217)
999285 CVE-2021-24209 WEB-WORDPRESS WP Super Cache Plugin Prior to 1.7.2 - Remote Code Execution Vulnerability in wp-cache-config.php (CVE-2021-24209)
999286 CVE-2021-24209 WEB-WORDPRESS WP Super Cache Plugin Prior to 1.7.2 - Arbitrary Code Injection Vulnerability (CVE-2021-24209)
999287 CVE-2021-24165 WEB-WORDPRESS Ninja Forms Plugin Prior to 3.4.34 - Open Redirect Vulnerability (CVE-2021-24165)
999288 CVE-2021-21975 WEB-MISC vRealize Operations Manager - Unauthenticated Server Side Request Forgery Vulnerability (CVE-2021-21975)
999289 CVE-2020-35578 WEB-MISC Nagios XI Prior to 5.8.0 - Remote Code Execution Vulnerability (CVE-2020-35578)
999290 CVE-2020-2766 WEB-MISC Oracle WebLogic Server - Unauthenticated SSRF Vulnerability (CVE-2020-2766)
999291 CVE-2020-17523 WEB-MISC Apache Shiro Prior to 1.7.1 - Authentication Bypass Vulnerability Via Space (CVE-2020-17523)
999292 CVE-2020-17523 WEB-MISC Apache Shiro Prior to 1.7.1 - Authentication Bypass Vulnerability Via Dot (CVE-2020-17523)
999293 CVE-2020-15160 WEB-MISC PrestaShop Prior to 1.7.6.8 - SQL Injection Vulnerability (CVE-2020-15160)
2021 年 4 月的签名更新