QID 376085

Date Published: 2021-11-17

QID 376085: Citrix ADC and Citrix Gateway Unauthenticated Denial of Service (DoS) Vulnerability (CTX330728)

Citrix NetScaler Gateway provides secure access control management solution.

Citrix ADC provides proven L4-7 load balancing and global server load balancing (GSLB) to ensure the best application performance and reliability.
Unauthenticated Denial of Service(DoS) has been identified in Citrix Application Delivery Controller (ADC) formerly known as NetScaler ADC and Citrix Gateway formerly known as NetScaler Gateway.

Affected Versions:
Citrix ADC and Citrix Gateway 13.1 before 13.1-4.43
Citrix ADC and Citrix Gateway 13.0 before 13.0-83.27
Citrix ADC and Citrix Gateway 12.1 before 12.1-63.22

QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of Citrix ADC/Netscaler.
NOTE:Access to NSIP or SNIP with management interface access
NOTE:Appliance must be configured as a VPN (Gateway) or AAA virtual server

Successful exploitation of this vulnerability may lead to Unauthenticated Denial of Service(DoS) or Temporary disruption of the Management GUI, Nitro API and RPC communication

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to CTX330728 for information pertaining to remediating this vulnerability.

    Vendor References

    CVEs related to QID 376085

    Software Advisories
    Advisory ID Software Component Link
    CTX330728 URL Logo support.citrix.com/article/CTX330728