Vulnerability Description
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Application Delivery Controller Firmware | >= 11.1, < 11.1-65.22 |
| Citrix | Application Delivery Controller | - |
| Citrix | Mpx\/Sdx 14030 Fips | - |
| Citrix | Mpx\/Sdx 14060 Fips | - |
| Citrix | Mpx\/Sdx 14080 Fips | - |
| Citrix | Mpx 15030-50G Fips | - |
| Citrix | Mpx 15040-50G Fips | - |
| Citrix | Mpx 15060-50G Fips | - |
| Citrix | Mpx 15080-50G Fips | - |
| Citrix | Mpx 15100-50G Fips | - |
| Citrix | Mpx 15120-50G Fips | - |
| Citrix | Mpx 8905 Fips | - |
| Citrix | Mpx 8910 Fips | - |
| Citrix | Mpx 8920 Fips | - |
| Citrix | Gateway | >= 12.1, < 12.1-62.27 |
| Citrix | Netscaler Gateway | >= 11.1, < 11.1-65.22 |
Related Weaknesses (CWE)
References
- https://support.citrix.com/article/CTX319135Vendor Advisory
- https://support.citrix.com/article/CTX319135Vendor Advisory
FAQ
What is CVE-2021-22927?
CVE-2021-22927 is a vulnerability with a CVSS score of 8.1 (HIGH). A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
How severe is CVE-2021-22927?
CVE-2021-22927 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22927?
Check the references section above for vendor advisories and patch information. Affected products include: Citrix Application Delivery Controller Firmware, Citrix Application Delivery Controller, Citrix Mpx\/Sdx 14030 Fips, Citrix Mpx\/Sdx 14060 Fips, Citrix Mpx\/Sdx 14080 Fips.