Vulnerabilities > Citrix > Gateway > 13.0.64.35

DATE CVE VULNERABILITY TITLE RISK
2023-07-10 CVE-2023-24487 Unspecified vulnerability in Citrix Application Delivery Controller and Gateway
Arbitrary file read in Citrix ADC and Citrix Gateway?
network
low complexity
citrix
7.5
2023-07-10 CVE-2023-24488 Cross-site Scripting vulnerability in Citrix Application Delivery Controller and Gateway
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway? in allows and attacker to perform cross site scripting
network
low complexity
citrix CWE-79
6.1
2023-01-26 CVE-2022-27507 Resource Exhaustion vulnerability in Citrix Application Delivery Controller and Gateway
Authenticated denial of service
network
low complexity
citrix CWE-400
6.5
2022-11-08 CVE-2022-27510 Improper Authentication vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Unauthorized access to Gateway user capabilities
network
low complexity
citrix CWE-287
critical
9.8
2022-11-08 CVE-2022-27513 Insufficient Verification of Data Authenticity vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Remote desktop takeover via phishing
network
low complexity
citrix CWE-345
critical
9.6
2022-11-08 CVE-2022-27516 Improper Restriction of Excessive Authentication Attempts vulnerability in Citrix Application Delivery Controller Firmware and Gateway
User login brute force protection functionality bypass
network
low complexity
citrix CWE-307
critical
9.8
2021-12-07 CVE-2021-22955 Resource Exhaustion vulnerability in Citrix Application Delivery Controller Firmware and Gateway
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
network
citrix CWE-400
4.3
2021-12-07 CVE-2021-22956 Resource Exhaustion vulnerability in Citrix products
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
network
citrix CWE-400
4.3
2021-08-05 CVE-2021-22919 Allocation of Resources Without Limits or Throttling vulnerability in Citrix products
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO.
network
low complexity
citrix CWE-770
5.0
2021-08-05 CVE-2021-22927 Session Fixation vulnerability in Citrix products
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
network
citrix CWE-384
5.8