Citrix ADC
cpe:2.3:h:citrix:application_delivery_controller:*:*:*:*:*:*:*, +7 more
- < 13.0-58.30
- < 12.1-57.18
- < 12.0-63.21
- < 11.1-64.14
- < 10.5-70.18
This vulnerability is being actively exploited in the wild.
A vulnerability allowing improper input validation has been identified in Citrix ADC, Citrix Gateway, and certain Citrix SD-WAN WANOP appliance models. This vulnerability affects multiple versions of Citrix ADC and Citrix Gateway, as well as Citrix SD-WAN WANOP versions prior to 11.1.1a, 11.0.3d, and 10.2.7. The issue allows limited information disclosure to users with low privileges.
Exploitation of this vulnerability could lead to unauthorized information disclosure to low-privileged users.
Citrix has released patches for all supported versions of Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP. Users are advised to update to the latest version. Instructions for downloading the updates are available on the Citrix website. For Citrix Gateway Plug-in for Linux, users should log in to an updated version of Citrix Gateway to receive the update.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.