First published: Tue Dec 07 2021(Updated: )
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Application Delivery Controller Firmware | <=11.1-65.23 | |
Citrix Application Delivery Controller Firmware | >=12.1<12.1-63.22 | |
Citrix Application Delivery Controller Firmware | >=13.0<13.0-83.27 | |
Citrix Application Delivery Controller | ||
Citrix Gateway | <11.1-65.23 | |
Citrix Gateway | >=12.1<12.1-63.22 | |
Citrix Gateway | >=13.0<13.0-83.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22955 is an unauthenticated denial of service vulnerability that exists in Citrix ADC <13.0-83.27, <12.1-63.22, and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server.
CVE-2021-22955 can cause a temporary disruption of the Management GUI, Nitro API, and RPC communication on Citrix ADC when configured as a VPN (Gateway) or AAA virtual server.
CVE-2021-22955 has a severity rating of 7.5 (high).
Citrix ADC versions <13.0-83.27, <12.1-63.22, and 11.1-65.23 are affected by CVE-2021-22955.
To fix CVE-2021-22955, it is recommended to upgrade to a version of Citrix ADC that is not affected by the vulnerability. Check the Citrix support article for detailed instructions.