CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Arbitrary file read in Citrix ADC and Citrix Gateway | 7.5 |
High |
||
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | 6.1 |
Medium |
||
Authenticated denial of service | 6.5 |
Medium |
||
User login brute force protection functionality bypass | 9.8 |
Critical |
||
Unauthorized access to Gateway user capabilities | 9.8 |
Critical |
||
Remote desktop takeover via phishing | 9.6 |
Critical |
||
Unauthenticated redirection to a malicious website | 6.1 |
Medium |
||
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | 7.5 |
High |
||
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session. | 6.5 |
Medium |
||
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed. | 7.5 |
High |
||
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | 8.1 |
High |