CVE-2014-2690: Citrix Vdi-In-A-Box

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.

Affected products

  • Citrix Vdi-In-A-Box: version 5.3.0 only; version 5.3.1 only; version 5.3.2 only; version 5.3.3 only; version 5.3.4 only; version 5.3.5 only; …

Published 2014-04-15. Last modified 2026-06-17.