QID 375755

Date Published: 2021-08-02

QID 375755: Citrix ADC And Citrix Gateway Account Hijacking Vulnerability (CTX319135)

Citrix NetScaler Gateway provides secure access control management solution.

Citrix ADC provides proven L4-7 load balancing and global server load balancing (GSLB) to ensure the best application performance and reliability.
Multiple vulnerability has been identified in Citrix Application Delivery Controller (ADC) formerly known as NetScaler ADC and Citrix Gateway formerly known as NetScaler Gateway that, if exploited, could result in a number of security issues.

Affected Versions:
Citrix ADC and Citrix Gateway 13.0-82.42
Citrix ADC and Citrix Gateway 12.1-62.25

QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of Citrix ADC/NetScaler.

Successful exploitation could allow an attacker to steal a valid user session via SAML authentication hijack through a phishing attack

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CTX319135 for information pertaining to remediating this vulnerability.

    Vendor References

    CVEs related to QID 375755

    Software Advisories
    Advisory ID Software Component Link
    CTX319135 URL Logo support.citrix.com/article/CTX319135