An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
2019-12-27T14:15:12.070
2025-04-03T19:51:47.203
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | citrix | application_delivery_controller_firmware | 10.5 | Yes |
Operating System | citrix | application_delivery_controller_firmware | 11.1 | Yes |
Operating System | citrix | application_delivery_controller_firmware | 12.0 | Yes |
Operating System | citrix | application_delivery_controller_firmware | 12.1 | Yes |
Operating System | citrix | application_delivery_controller_firmware | 13.0 | Yes |
Hardware | citrix | application_delivery_controller | - | No |
Operating System | citrix | netscaler_gateway_firmware | 10.5 | Yes |
Operating System | citrix | netscaler_gateway_firmware | 11.1 | Yes |
Operating System | citrix | netscaler_gateway_firmware | 12.0 | Yes |
Operating System | citrix | netscaler_gateway_firmware | 12.1 | Yes |
Hardware | citrix | netscaler_gateway | - | No |
Operating System | citrix | gateway_firmware | 13.0 | Yes |
Hardware | citrix | gateway | - | No |