Show filters
94 Total Results
Displaying 21-30 of 94
Sort by:
Attacker Value
Unknown

CVE-2022-27513

Disclosure Date: November 08, 2022 (last updated October 19, 2023)
Remote desktop takeover via phishing
Attacker Value
Unknown

CVE-2022-27516

Disclosure Date: November 08, 2022 (last updated October 19, 2023)
User login brute force protection functionality bypass
Attacker Value
Unknown

CVE-2022-27509

Disclosure Date: July 26, 2022 (last updated October 08, 2023)
Unauthenticated redirection to a malicious website
Attacker Value
Unknown

CVE-2022-27507

Disclosure Date: May 26, 2022 (last updated October 08, 2023)
Authenticated denial of service
Attacker Value
Unknown

CVE-2022-27508

Disclosure Date: May 26, 2022 (last updated October 08, 2023)
Unauthenticated denial of service
Attacker Value
Unknown

CVE-2021-22956

Disclosure Date: December 07, 2021 (last updated October 07, 2023)
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Attacker Value
Unknown

CVE-2021-22955

Disclosure Date: December 07, 2021 (last updated October 07, 2023)
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Attacker Value
Unknown

CVE-2002-20001

Disclosure Date: November 11, 2021 (last updated January 11, 2024)
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Attacker Value
Unknown

CVE-2021-22927

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
Attacker Value
Unknown

CVE-2021-22919

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.