Citrix Application Delivery Controller Firmware vulnerabilities
27 known vulnerabilities affecting citrix/application_delivery_controller_firmware.
Total CVEs
27
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL4HIGH10MEDIUM13
Vulnerabilities
Page 2 of 2
CVE-2021-22919P4HIGHCVSS 7.5≥ 11.1, < 11.1-65.22≥ 12.1, < 12.1-62.27+2 more2021-08-05
CVE-2021-22919 [HIGH] CWE-770 CVE-2021-22919: A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gatew
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
nvd
CVE-2019-18177P4MEDIUMCVSS 6.5fixed in 13.0-58.302022-12-26
CVE-2019-18177 [MEDIUM] CWE-200 CVE-2019-18177: In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
nvd
CVE-2017-17549P4MEDIUMCVSS 5.9v10.5v11.0+2 more2017-12-13
CVE-2017-17549 [MEDIUM] CWE-200 CVE-2017-17549: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client Certificates and a Diffie-Hellman Ephemer
nvd
CVE-2020-8245P4MEDIUMCVSS 6.1≥ 11.1, < 11.1-65.12≥ 12.1, < 12.1-58.15+1 more2020-09-18
CVE-2020-8245 [MEDIUM] CWE-79 CVE-2020-8245: Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and Ne
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1
nvd
CVE-2020-8299P4MEDIUMCVSS 6.5≥ 11.1, < 11.1-65.20≥ 12.1, < 12.1-61.18+2 more2021-06-16
CVE-2020-8299 [MEDIUM] CWE-400 CVE-2020-8299: Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 1
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segmen
nvd
CVE-2022-27509P4MEDIUMCVSS 6.1≥ 12.1, < 12.1-65.15≥ 13.0, < 13.0-86.17+2 more2022-07-28
CVE-2022-27509 [MEDIUM] CWE-601 CVE-2022-27509: Unauthenticated redirection to a malicious website
Unauthenticated redirection to a malicious website
nvd
CVE-2020-8198P4MEDIUMCVSS 6.1≥ 10.5, < 10.5-70.18≥ 11.1, < 11.1-64.14+3 more2020-07-10
CVE-2020-8198 [MEDIUM] CWE-79 CVE-2020-8198: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 1
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).
nvd
← Previous2 / 2