Citrix Application Delivery Controller Firmware vulnerabilities

27 known vulnerabilities affecting citrix/application_delivery_controller_firmware.

Total CVEs
27
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL4HIGH10MEDIUM13

Vulnerabilities

Page 1 of 2
CVE-2019-18177MEDIUMCVSS 6.5fixed in 13.0-58.302022-12-26
CVE-2019-18177 [MEDIUM] CWE-200 CVE-2019-18177: In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
nvd
CVE-2022-27516CRITICALCVSS 9.8≥ 12.1, < 12.1-65.21≥ 13.0, < 13.0-88.12+2 more2022-11-08
CVE-2022-27516 [CRITICAL] CWE-693 CVE-2022-27516: User login brute force protection functionality bypass User login brute force protection functionality bypass
nvd
CVE-2022-27509MEDIUMCVSS 6.1≥ 12.1, < 12.1-65.15≥ 13.0, < 13.0-86.17+2 more2022-07-28
CVE-2022-27509 [MEDIUM] CWE-601 CVE-2022-27509: Unauthenticated redirection to a malicious website Unauthenticated redirection to a malicious website
nvd
CVE-2021-22955HIGHCVSS 7.5≤ 11.1-65.23≥ 12.1, < 12.1-63.22+1 more2021-12-07
CVE-2021-22955 [HIGH] CWE-400 CVE-2021-22955: A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
nvd
CVE-2021-22956HIGHCVSS 7.5fixed in 11.1-65.23≥ 12.1, < 12.1-63.22+1 more2021-12-07
CVE-2021-22956 [HIGH] CWE-400 CVE-2021-22956: An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
nvd
CVE-2021-22919HIGHCVSS 7.5≥ 11.1, < 11.1-65.22≥ 12.1, < 12.1-62.27+2 more2021-08-05
CVE-2021-22919 [HIGH] CWE-770 CVE-2021-22919: A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gatew A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
nvd
CVE-2021-22927HIGHCVSS 8.1≥ 11.1, < 11.1-65.22≥ 12.1, < 12.1-62.27+2 more2021-08-05
CVE-2021-22927 [HIGH] CWE-384 CVE-2021-22927: A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
nvd
CVE-2020-8300MEDIUMCVSS 6.5≥ 11.1, < 11.1-65.20≥ 12.1, < 12.1-62.23+2 more2021-06-16
CVE-2020-8300 [MEDIUM] CWE-284 CVE-2020-8300: Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12. Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to b
nvd
CVE-2020-8299MEDIUMCVSS 6.5≥ 11.1, < 11.1-65.20≥ 12.1, < 12.1-61.18+2 more2021-06-16
CVE-2020-8299 [MEDIUM] CWE-400 CVE-2020-8299: Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 1 Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segmen
nvd
CVE-2020-8246HIGHCVSS 7.5≥ 11.1, < 11.1-65.12≥ 12.1, < 12.1-58.15+1 more2020-09-18
CVE-2020-8246 [HIGH] CWE-400 CVE-2020-8246: Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 1 Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0
nvd
CVE-2020-8247HIGHCVSS 8.8≥ 11.1, < 11.1-65.12≥ 12.1, < 12.1-58.15+1 more2020-09-18
CVE-2020-8247 [HIGH] CWE-269 CVE-2020-8247: Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 1 Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0
nvd
CVE-2020-8245MEDIUMCVSS 6.1≥ 11.1, < 11.1-65.12≥ 12.1, < 12.1-58.15+1 more2020-09-18
CVE-2020-8245 [MEDIUM] CWE-79 CVE-2020-8245: Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and Ne Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1
nvd
CVE-2020-8197HIGHCVSS 8.8≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8197 [HIGH] CVE-2020-8197: Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1 Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.
nvd
CVE-2020-8187HIGHCVSS 7.5≥ 11.1, < 11.1-63.9≥ 12.0, < 12.0-62.102020-07-10
CVE-2020-8187 [HIGH] CWE-20 CVE-2020-8187: Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.
nvd
CVE-2020-8190HIGHCVSS 7.5≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8190 [HIGH] CWE-281 CVE-2020-8190: Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
nvd
CVE-2020-8198MEDIUMCVSS 6.1≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8198 [MEDIUM] CWE-79 CVE-2020-8198: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 1 Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).
nvd
CVE-2020-8195MEDIUMCVSS 6.5KEVPoC≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8195 [MEDIUM] CWE-20 CVE-2020-8195: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 1 Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
nvd
CVE-2020-8196MEDIUMCVSS 4.3KEVPoC≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8196 [MEDIUM] CWE-284 CVE-2020-8196: Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12. Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
nvd
CVE-2020-8193MEDIUMCVSS 6.5KEVPoC≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8193 [MEDIUM] CWE-284 CVE-2020-8193: Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12. Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
nvd
CVE-2020-8191MEDIUMCVSS 6.1ExploitedPoC≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8191 [MEDIUM] CWE-79 CVE-2020-8191: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 1 Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
nvd