Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Citrix Adc | — | Apply the fixed builds that have been released for Citrix ADC versions 12.1 and Citrix Gateway versions 12.1.Apply the fixed builds that have been released for Citrix ADC versions 11.1 and Citrix Gateway versions 11.1.Apply the fixed builds that have been released for Citrix ADC versions 10.5 and Citrix Gateway versions 10.5.Apply the fixed builds that have been released for Citrix ADC versions 13.0 and Citrix Gateway versions 13.0Apply the fixed builds that have been released for Citrix ADC versions 12.0 and Citrix Gateway versions 12.0. | Jul 7, 2020 | Jul 7, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub