Executive brief
Citrix ADC, Gateway, and SD-WAN WANOP appliances contain an authorization bypass vulnerability due to improper access control. An unauthenticated attacker with access to the NetScaler IP (NSIP) can gain unauthorized access to certain URL endpoints.
Affected products
- Citrix ADC before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, 10.5-70.18
- Citrix Gateway before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, 10.5-70.18
- Citrix SD-WAN WANOP before 11.1.1a, 11.0.3d, 10.2.7
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed