Citrix NetScaler ADC
cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:*:*:*:*:*:*:*, +2 more
- >= 14.1-66.54, < 14.1-66.59
A race condition vulnerability has been identified in Citrix NetScaler ADC and NetScaler Gateway, specifically in version 14.1-66.54. When the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, this vulnerability can lead to a mix-up of user sessions.
Exploitation of this vulnerability causes a user session mix-up, where sessions can be incorrectly assigned or shared between users, potentially leading to unauthorized access or actions within a user's session.
Affected customers are advised to upgrade to NetScaler ADC and NetScaler Gateway versions 14.1-66.59 or later, 13.1-62.23 or later, or for NetScaler ADC 13.1-FIPS and 13.1-NDcPP, version 13.1.37.262 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.