QID 376795
QID 376795: Citrix Application Delivery Controller (ADC) and Citrix Gateway URL Redirection Vulnerability
Citrix ADC provides proven L4-7 load balancing and global server load balancing (GSLB) to ensure the best application performance and reliability.
A vulnerability has been discovered in Citrix ADC and Citrix Gateway which enables an attacker to create a specially crafted URL that redirects to a malicious website
Affected Versions:
Citrix ADC and Citrix Gateway 13.1 before 13.1-24.38
Citrix ADC and Citrix Gateway 13.0 before 13.0-86.17
Citrix ADC and Citrix Gateway 12.1 before 12.1-65.15
Citrix ADC and Citrix Gateway 12.1-FIPS before 12.1-55.282
Citrix ADC and Citrix Gateway 12.1-NDcPP before 12.1-55.282
QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of Citrix ADC
Successful exploitation of vulnerability may allow attacker in potentially masquerading a malicious URL as trusted.
Customers are advised to refer to CTX457836 for information pertaining to remediating this vulnerability.
CVEs related to QID 376795
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CTX457836 |
|