Lucene search

K
cve[email protected]CVE-2021-22956
HistoryDec 07, 2021 - 2:15 p.m.

CVE-2021-22956

2021-12-0714:15:08
CWE-400
web.nvd.nist.gov
22
3
cve-2021-22956
citrix adc
vulnerability
resource consumption
nsip
snip
management interface

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

38.4%

An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.

Affected configurations

NVD
Node
citrixapplication_delivery_controller_firmwareRange<11.1-65.23
OR
citrixapplication_delivery_controller_firmwareRange12.112.1-63.22
OR
citrixapplication_delivery_controller_firmwareRange13.013.0-83.27
AND
citrixapplication_delivery_controllerMatch-
Node
citrixgatewayRange<11.1-65.23
OR
citrixgatewayRange12.112.1-63.22
OR
citrixgatewayRange13.013.0-65.23
Node
citrixsd-wanRange<10.2.9cwanop
OR
citrixsd-wanRange11.4.011.4.2wanop

CNA Affected

[
  {
    "product": "Citrix ADC, Citrix Gateway, Citrix SDWAN",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Citrix ADC 11.1,12.1,13.0,13.1"
      }
    ]
  }
]

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

38.4%