ID

VAR-202108-0264


CVE

CVE-2021-22919


TITLE

plural  Citrix  Product vulnerabilities related to resource allocation without restrictions or throttling

Trust: 0.8

sources: JVNDB: JVNDB-2021-009766

DESCRIPTION

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed

Trust: 1.8

sources: NVD: CVE-2021-22919 // JVNDB: JVNDB-2021-009766 // VULHUB: VHN-381393 // VULMON: CVE-2021-22919

AFFECTED PRODUCTS

vendor:citrixmodel:application delivery controllerscope:gteversion:11.1

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:ltversion:11.2.3.b

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:13.0-82.45

Trust: 1.0

vendor:citrixmodel:netscaler gatewayscope:gteversion:11.1

Trust: 1.0

vendor:citrixmodel:gatewayscope:ltversion:12.1-62.27

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:ltversion:11.4.0.a

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:12.1-55.238

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:ltversion:10.2.9.b

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:gteversion:11.4

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:11.1-65.22

Trust: 1.0

vendor:citrixmodel:gatewayscope:gteversion:12.1

Trust: 1.0

vendor:citrixmodel:gatewayscope:ltversion:13.0-82.45

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:gteversion:11.3

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:ltversion:11.3.2.a

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:ltversion:12.1-62.27

Trust: 1.0

vendor:citrixmodel:gatewayscope:gteversion:13.0

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:gteversion:11.2

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:gteversion:12.1

Trust: 1.0

vendor:citrixmodel:sd-wan wanopscope:gteversion:10.2

Trust: 1.0

vendor:citrixmodel:application delivery controllerscope:gteversion:13.0

Trust: 1.0

vendor:citrixmodel:netscaler gatewayscope:ltversion:11.1-65.22

Trust: 1.0

vendor:シトリックス システムズmodel:citrix sdwan wan-opscope: - version: -

Trust: 0.8

vendor:シトリックス システムズmodel:netscaler gatewayscope: - version: -

Trust: 0.8

vendor:シトリックス システムズmodel:citrix application delivery controllerscope: - version: -

Trust: 0.8

vendor:シトリックス システムズmodel:citrix gatewayscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-009766 // NVD: CVE-2021-22919

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22919
value: HIGH

Trust: 1.0

NVD: CVE-2021-22919
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202107-1476
value: HIGH

Trust: 0.6

VULHUB: VHN-381393
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22919
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-381393
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-22919
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22919
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-381393 // JVNDB: JVNDB-2021-009766 // CNNVD: CNNVD-202107-1476 // NVD: CVE-2021-22919

PROBLEMTYPE DATA

problemtype:CWE-770

Trust: 1.1

problemtype:Allocation of resources without limits or throttling (CWE-770) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-381393 // JVNDB: JVNDB-2021-009766 // NVD: CVE-2021-22919

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202107-1476

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202107-1476

PATCH

title:CTX319135url:https://support.citrix.com/article/CTX319135

Trust: 0.8

sources: JVNDB: JVNDB-2021-009766

EXTERNAL IDS

db:NVDid:CVE-2021-22919

Trust: 3.4

db:JVNDBid:JVNDB-2021-009766

Trust: 0.8

db:AUSCERTid:ESB-2021.2434

Trust: 0.6

db:CNNVDid:CNNVD-202107-1476

Trust: 0.6

db:VULHUBid:VHN-381393

Trust: 0.1

db:VULMONid:CVE-2021-22919

Trust: 0.1

sources: VULHUB: VHN-381393 // VULMON: CVE-2021-22919 // JVNDB: JVNDB-2021-009766 // CNNVD: CNNVD-202107-1476 // NVD: CVE-2021-22919

REFERENCES

url:https://support.citrix.com/article/ctx319135

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-22919

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2021.2434

Trust: 0.6

sources: VULHUB: VHN-381393 // VULMON: CVE-2021-22919 // JVNDB: JVNDB-2021-009766 // CNNVD: CNNVD-202107-1476 // NVD: CVE-2021-22919

SOURCES

db:VULHUBid:VHN-381393
db:VULMONid:CVE-2021-22919
db:JVNDBid:JVNDB-2021-009766
db:CNNVDid:CNNVD-202107-1476
db:NVDid:CVE-2021-22919

LAST UPDATE DATE

2024-08-14T13:43:26.381000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-381393date:2021-08-16T00:00:00
db:JVNDBid:JVNDB-2021-009766date:2022-05-19T08:10:00
db:CNNVDid:CNNVD-202107-1476date:2021-08-17T00:00:00
db:NVDid:CVE-2021-22919date:2021-08-16T16:54:35.763

SOURCES RELEASE DATE

db:VULHUBid:VHN-381393date:2021-08-05T00:00:00
db:JVNDBid:JVNDB-2021-009766date:2022-05-19T00:00:00
db:CNNVDid:CNNVD-202107-1476date:2021-07-20T00:00:00
db:NVDid:CVE-2021-22919date:2021-08-05T21:15:10.997