← Vulnerability feed

Vulnerability record · CVE-2021-22920 · published 5 August 2021

CVE-2021-22920: Citrix application delivery management improper access control vulnerability

Citrix · Application Delivery Management

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.

6.5 CVSS 3.1 Medium EPSS 0.92% · top 41.3% CWE-284 · Improper access control
6.5CVSS 3.1 base score, v2 4.3
0.92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22920 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-9548Citrix application delivery management vulnerabilityCitrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.EPSS 1.5%9.8CVE-2022-27510Citrix gateway authentication bypass via alternate path vulnerabilityUnauthorized access to Gateway user capabilitiesEPSS 1.1%9.8CVE-2022-27516Citrix gateway improper restriction of authentication attempts vulnerabilityUser login brute force protection functionality bypassEPSS 0.64%9.6CVE-2022-27513Citrix gateway insufficient verification of data authenticity vulnerabilityRemote desktop takeover via phishingEPSS 0.29%8.8CVE-2020-8247Citrix application delivery controller firmware improper privilege management vulnerabilityCitrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18…EPSS 1.4%8.8CVE-2019-17366Citrix application delivery management vulnerabilityCitrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.EPSS 1.3%8.1CVE-2022-27511Citrix application delivery management improper access control vulnerabilityCorruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device…EPSS 12%8.1CVE-2021-22927Citrix application delivery controller firmware vulnerabilityA session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacke…EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2021-22920), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.