Citrix Netscaler Access Gateway Firmware vulnerabilities
7 known vulnerabilities affecting citrix/netscaler_access_gateway_firmware.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2014-4347MEDIUMCVSS 5.0v9.3v10.12014-07-16
CVE-2014-4347 [MEDIUM] CWE-200 CVE-2014-4347: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gatewa
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.
nvd
CVE-2014-4346MEDIUMCVSS 4.3v10.12014-07-16
CVE-2014-4346 [MEDIUM] CWE-79 CVE-2014-4346: Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Applic
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-1899MEDIUMCVSS 4.3v9.3v9.3.61.5+4 more2014-05-02
CVE-2014-1899 [MEDIUM] CWE-79 CVE-2014-1899: Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-2882CRITICALCVSS 10.0≤ 10.1.ev9.32014-05-01
CVE-2014-2882 [CRITICAL] CVE-2014-2882: Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller
Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.
nvd
CVE-2014-2881CRITICALCVSS 10.0v9.3≤ 10.1.e2014-05-01
CVE-2014-2881 [CRITICAL] CVE-2014-2881: Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI J
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.
nvd
CVE-2013-2767MEDIUMCVSS 5.4≤ 9.3.61.5v9.1+4 more2013-04-25
CVE-2013-2767 [MEDIUM] CVE-2013-2767: Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.
nvd
CVE-2009-2213MEDIUMCVSS 6.5≤ 8.1v7.0+2 more2009-06-25
CVE-2009-2213 [MEDIUM] CWE-863 CVE-2009-2213: The default configuration of the Security global settings on the Citrix NetScaler Access Gateway app
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.
nvd