CVE-2009-2213
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote…
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- citrix/netscaler access gateway firmware · citrix/netscaler access gateway
- Source
- cve@mitre.org
References
- http://support.citrix.com/article/CTX118770Broken Link, Vendor Advisory
- http://www.securityfocus.com/bid/35422Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1641Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51274Third Party Advisory, VDB Entry
- http://support.citrix.com/article/CTX118770Broken Link, Vendor Advisory
- http://www.securityfocus.com/bid/35422Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1641Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51274Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.