CVE-2022-27507: Authenticated denial of service
Published Jan 24, 2023
·Updated
Authenticated denial of service
Affected Software
8 affected components
Citrix Gateway>=12.1<12.1-64.17
Citrix Gateway>=13.0<13.0-85.19
Citrix Gateway>=13.1<13.1-21.50
Citrix Application Delivery Controller>=12.1<12.1-55.278
Citrix Application Delivery Controller>=12.1<12.1-55.278
Citrix Application Delivery Controller>=12.1<12.1-64.17
Citrix Application Delivery Controller>=13.0<13.0-85.19
Citrix Application Delivery Controller>=13.1<13.1-21.50
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-27507?
CVE-2022-27507 is a vulnerability that allows an authenticated attacker to carry out a denial of service attack on Citrix Gateway and Citrix Application Delivery Controller.
2
What is the severity of CVE-2022-27507?
CVE-2022-27507 has a severity rating of 6.5, which is considered medium.
3
What software is affected by CVE-2022-27507?
Citrix Gateway and Citrix Application Delivery Controller versions 12.1-64.17 to 13.1-21.50 are affected by CVE-2022-27507.
4
How can an attacker exploit CVE-2022-27507?
An attacker can exploit CVE-2022-27507 by sending specially crafted requests to the affected software, leading to a denial of service condition.
5
Is there a fix available for CVE-2022-27507?
Yes, Citrix has released security patches to address the vulnerability. It is recommended to update to the latest version of the affected software.