7.5

CVE-2021-22956

An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Application Delivery Controller Firmware Version >= 12.1 < 12.1-63.22
Citrix ≫ Application Delivery Controller Firmware Version >= 13.0 < 13.0-83.27
Citrix ≫ Gateway Version < 11.1-65.23
Citrix ≫ Gateway Version >= 12.1 < 12.1-63.22
Citrix ≫ Gateway Version >= 13.0 < 13.0-65.23
Citrix ≫ Sd-wan SwEdition wanop Version < 10.2.9c
Citrix ≫ Sd-wan SwEdition wanop Version >= 11.4.0 < 11.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.548
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://support.citrix.com/article/CTX330728
Vendor Advisory