Citrix Gateway vulnerabilities
15 known vulnerabilities affecting citrix/gateway.
Total CVEs
15
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2023-24487HIGHCVSS 7.5≥ 12.1, < 12.1-65.35≥ 13.0, < 13.0-90.11+1 more2023-07-10
CVE-2023-24487 [HIGH] CWE-253 CVE-2023-24487: Arbitrary file read in Citrix ADC and Citrix Gateway
Arbitrary file read in Citrix ADC and Citrix Gateway
nvd
CVE-2023-24488MEDIUMCVSS 6.1PoC≥ 12.1, < 12.1-65.35≥ 13.0, < 13.0-90.11+1 more2023-07-10
CVE-2023-24488 [MEDIUM] CWE-79 CVE-2023-24488: Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perfo
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
nvd
CVE-2019-18177MEDIUMCVSS 6.5fixed in 13.0-58.302022-12-26
CVE-2019-18177 [MEDIUM] CWE-200 CVE-2019-18177: In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
nvd
CVE-2022-27516CRITICALCVSS 9.8≥ 12.1, < 12.1-65.21≥ 13.0, < 13.0-88.12+1 more2022-11-08
CVE-2022-27516 [CRITICAL] CWE-693 CVE-2022-27516: User login brute force protection functionality bypass
User login brute force protection functionality bypass
nvd
CVE-2022-27509MEDIUMCVSS 6.1≥ 12.1, < 12.1-65.15≥ 13.0, < 13.0-86.17+1 more2022-07-28
CVE-2022-27509 [MEDIUM] CWE-601 CVE-2022-27509: Unauthenticated redirection to a malicious website
Unauthenticated redirection to a malicious website
nvd
CVE-2021-22955HIGHCVSS 7.5fixed in 11.1-65.23≥ 12.1, < 12.1-63.22+1 more2021-12-07
CVE-2021-22955 [HIGH] CWE-400 CVE-2021-22955: A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
nvd
CVE-2021-22956HIGHCVSS 7.5fixed in 11.1-65.23≥ 12.1, < 12.1-63.22+1 more2021-12-07
CVE-2021-22956 [HIGH] CWE-400 CVE-2021-22956: An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
nvd
CVE-2021-22919HIGHCVSS 7.5≥ 12.1, < 12.1-62.27≥ 13.0, < 13.0-82.452021-08-05
CVE-2021-22919 [HIGH] CWE-770 CVE-2021-22919: A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gatew
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
nvd
CVE-2021-22927HIGHCVSS 8.1≥ 12.1, < 12.1-62.27≥ 13.0, < 13.0-82.452021-08-05
CVE-2021-22927 [HIGH] CWE-384 CVE-2021-22927: A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
nvd
CVE-2021-22920MEDIUMCVSS 6.5v12.1-62.25v13.0-82.422021-08-05
CVE-2021-22920 [MEDIUM] CWE-284 CVE-2021-22920: A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gatew
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user se
nvd
CVE-2020-8300MEDIUMCVSS 6.5≥ 12.1, < 12.1-62.23≥ 13.0, < 13.0-82.412021-06-16
CVE-2020-8300 [MEDIUM] CWE-284 CVE-2020-8300: Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to b
nvd
CVE-2020-8299MEDIUMCVSS 6.5≥ 12.1, < 12.1-61.18≥ 13.0, < 13.0-76.292021-06-16
CVE-2020-8299 [MEDIUM] CWE-400 CVE-2020-8299: Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 1
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segmen
nvd
CVE-2020-8246HIGHCVSS 7.5≥ 11.1, < 11.1-65.12≥ 13.0, < 13.0-64.352020-09-18
CVE-2020-8246 [HIGH] CWE-400 CVE-2020-8246: Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 1
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0
nvd
CVE-2020-8247HIGHCVSS 8.8≥ 11.1, < 11.1-65.12≥ 13.0, < 13.0-64.352020-09-18
CVE-2020-8247 [HIGH] CWE-269 CVE-2020-8247: Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 1
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0
nvd
CVE-2020-8245MEDIUMCVSS 6.1≥ 11.1, < 11.1-65.12≥ 13.0, < 13.0-64.352020-09-18
CVE-2020-8245 [MEDIUM] CWE-79 CVE-2020-8245: Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and Ne
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1
nvd