Vulnerability Description
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Application Delivery Controller Firmware | <= 11.1-65.23 |
| Citrix | Application Delivery Controller | - |
| Citrix | Gateway | < 11.1-65.23 |
Related Weaknesses (CWE)
References
- https://support.citrix.com/article/CTX330728Vendor Advisory
- https://support.citrix.com/article/CTX330728Vendor Advisory
FAQ
What is CVE-2021-22955?
CVE-2021-22955 is a vulnerability with a CVSS score of 7.5 (HIGH). A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause...
How severe is CVE-2021-22955?
CVE-2021-22955 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22955?
Check the references section above for vendor advisories and patch information. Affected products include: Citrix Application Delivery Controller Firmware, Citrix Application Delivery Controller, Citrix Gateway.