Citrix Gateway 12.1-61.18

CPE Details

Citrix Gateway 12.1-61.18
12.1-61.18
2021-06-23
11h57 +00:00
2021-06-23
12h27 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:citrix:gateway:12.1-61.18:*:*:*:*:*:*:*

Informations

Vendor

citrix

Product

gateway

Version

12.1-61.18

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-24487 2023-07-10 20h51 +00:00 Arbitrary file read in Citrix ADC and Citrix Gateway 
7.5
High
CVE-2023-24488 2023-07-10 20h41 +00:00 Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting
6.1
Medium
CVE-2022-27507 2023-01-24 00h00 +00:00 Authenticated denial of service
6.5
Medium
CVE-2019-18177 2022-12-26 00h00 +00:00 In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
6.5
Medium
CVE-2022-27516 2022-11-08 21h26 +00:00 User login brute force protection functionality bypass
9.8
Critical
CVE-2022-27510 2022-11-08 21h26 +00:00 Unauthorized access to Gateway user capabilities
9.8
Critical
CVE-2022-27513 2022-11-08 21h26 +00:00 Remote desktop takeover via phishing
9.6
Critical
CVE-2022-27509 2022-07-28 13h11 +00:00 Unauthenticated redirection to a malicious website
6.1
Medium
CVE-2021-22956 2021-12-07 12h12 +00:00 An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
7.5
High
CVE-2021-22955 2021-12-07 12h12 +00:00 A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
7.5
High
CVE-2021-22919 2021-08-05 18h16 +00:00 A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
7.5
High
CVE-2021-22927 2021-08-05 18h16 +00:00 A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
8.1
High
CVE-2020-8300 2021-06-16 11h08 +00:00 Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
6.5
Medium