CVE-2014-2690: Citrix Vdi-In-A-Box
Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.
Affected products
- Citrix Vdi-In-A-Box: version 5.3.0 only; version 5.3.1 only; version 5.3.2 only; version 5.3.3 only; version 5.3.4 only; version 5.3.5 only; …
Published 2014-04-15. Last modified 2026-06-17.