CVE-2009-2213

MEDIUM

Citrix NetScaler Access Gateway <9.0 - Auth Bypass

Title source: llm

Description

The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.

Scores

CVSS v3 6.5
EPSS 0.0035
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-863
Status draft

Affected Products (5)

citrix/netscaler_access_gateway_firmware < 8.1
citrix/netscaler_access_gateway_firmware
citrix/netscaler_access_gateway_firmware
citrix/netscaler_access_gateway_firmware
citrix/netscaler_access_gateway

Timeline

Published Jun 25, 2009
Tracked Since Feb 18, 2026