CVE Vulnerabilities

CVE-2021-22920

Published: Aug 05, 2021 | Modified: Aug 13, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.

Affected Software

Name Vendor Start Version End Version
Application_delivery_management Citrix 12.1-62.25 (including) 12.1-62.25 (including)
Application_delivery_management Citrix 13.0-82.42 (including) 13.0-82.42 (including)
Gateway Citrix 12.1-62.25 (including) 12.1-62.25 (including)
Gateway Citrix 13.0-82.42 (including) 13.0-82.42 (including)

References