CVE-2022-26355
Last modified
CVE-2022-26355 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Federated Authentication Service | >= 7.17, <= 10.6 |
References
- https://support.citrix.com/article/CTX341587Vendor Advisory
- https://support.citrix.com/article/CTX341587Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-26355?
How severe is CVE-2022-26355?
How do I fix CVE-2022-26355?
Are you affected by CVE-2022-26355?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
