CVE-2022-27509: Unauthenticated redirection to a malicious website
Published Jul 28, 2022
·Updated
Unauthenticated redirection to a malicious website
Affected Software
9 affected components
Citrix Gateway>=12.1<12.1-65.15
Citrix Gateway>=13.0<13.0-86.17
Citrix Gateway>=13.1<13.1-24.38
Citrix Application Delivery Controller Firmware>=12.1<12.1-65.15
Citrix Application Delivery Controller Firmware>=13.0<13.0-86.17
Citrix Application Delivery Controller Firmware>=13.1<13.1-24.38
Citrix Application Delivery Controller
Citrix Application Delivery Controller Firmware>=12.1<12.1-55.282
Citrix Application Delivery Controller Firmware>=12.1<12.1-55.282
Event History
Jul 28, 2022
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-27509?
CVE-2022-27509 is a vulnerability that allows unauthenticated redirection to a malicious website.
2
Which software is affected by CVE-2022-27509?
Citrix Gateway versions 12.1-65.15, 13.0-86.17, and 13.1-24.38, as well as Citrix Application Delivery Controller Firmware versions 12.1-65.15, 13.0-86.17, and 13.1-24.38 are affected by CVE-2022-27509.
3
What is the severity of CVE-2022-27509?
CVE-2022-27509 has a severity rating of 6.1, which is considered medium.
4
How can I mitigate CVE-2022-27509?
To mitigate CVE-2022-27509, it is recommended to update Citrix Gateway and Citrix Application Delivery Controller Firmware to versions that are not vulnerable.
5
Where can I find more information about CVE-2022-27509?
You can find more information about CVE-2022-27509 on the Citrix support website at the following link: https://support.citrix.com/article/CTX457836