CVE-2021-22955: High severity Citrix Application Delivery Controller Firmware vulnerability
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22955?
CVE-2021-22955 is an unauthenticated denial of service vulnerability that exists in Citrix ADC <13.0-83.27, <12.1-63.22, and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server.
How does CVE-2021-22955 impact Citrix ADC?
CVE-2021-22955 can cause a temporary disruption of the Management GUI, Nitro API, and RPC communication on Citrix ADC when configured as a VPN (Gateway) or AAA virtual server.
What is the severity of CVE-2021-22955?
CVE-2021-22955 has a severity rating of 7.5 (high).
Which versions of Citrix ADC are affected by CVE-2021-22955?
Citrix ADC versions <13.0-83.27, <12.1-63.22, and 11.1-65.23 are affected by CVE-2021-22955.
How can I fix CVE-2021-22955?
To fix CVE-2021-22955, it is recommended to upgrade to a version of Citrix ADC that is not affected by the vulnerability. Check the Citrix support article for detailed instructions.