← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-22920

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
EPSS Probability:0.92%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-284 ↗Improper Access Control - Generic (CWE-284)

Affected Products & Versions

Vendor Product Affected Versions
citrix application_delivery_management 12.1-62.25, 13.0-82.42
citrix gateway 12.1-62.25, 13.0-82.42

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.918%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2021-01-06T00:00:00
Published2021-08-05T20:16:49
Last Updated2024-08-03T18:58:25

LINK COPIED TO CLIPBOARD