Access Gateway
Vendor:
First CVE: Sep 19, 2006 · Active for 19 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Access Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2006
19 years ago
Most Recent CVE
Mar 19, 2013
4,875 days ago
CVE Severity & Scoring
Access Gateway14 CVEs
57%
43%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2882HIGH Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 befo | Jul 21, 2011 | 9.3 | 78 | NO | YES |
CVE-2010-4566HIGH The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Ga | Jan 14, 2011 | 9.3 | 65 | NO | YES |
CVE-2011-2883HIGH The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validat | Jul 21, 2011 | 9.3 | 29 | NO | NO |
CVE-2008-2528HIGH Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "a | Jun 3, 2008 | 10.0 | 27 | NO | NO |
CVE-2007-4013HIGH Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin di | Jul 26, 2007 | 9.3 | 24 | NO | NO |
CVE-2007-4017HIGH Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain co | Jul 26, 2007 | 7.6 | 20 | NO | NO |
CVE-2006-6572MEDIUM Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access | Dec 15, 2006 | 6.5 | 19 | NO | NO |
CVE-2007-0011MEDIUM The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependen | Nov 5, 2007 | 5.0 | 18 | NO | NO |
CVE-2007-4016MEDIUM Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary | Jul 26, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-4018MEDIUM Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors. | Jul 26, 2007 | 6.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
14.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Access Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1-104.5 | 1 | 9.3 | 27.8% | 0 | 1 |
| 9.1 | 2 | 9.3 | 28.9% | 0 | 1 |
| 9.0.71.3 | 1 | 9.3 | 27.8% | 0 | 1 |
| 9.0 | 2 | 9.3 | 28.9% | 0 | 1 |
| 8.1-69.4 | 1 | 9.3 | 27.8% | 0 | 1 |
| 8.1 | 2 | 9.3 | 28.9% | 0 | 1 |
| 8.0 | 1 | 9.3 | 27.8% | 0 | 1 |
| .8.0 | 1 | 9.3 | 27.8% | 0 | 1 |
| 5.4 | 1 | 5.0 | 1.4% | 0 | 0 |
| 5.3 | 1 | 5.0 | 1.4% | 0 | 0 |
| 5.2 | 1 | 5.0 | 1.4% | 0 | 0 |
| 5.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 5.0 | 1 | 5.0 | 1.4% | 0 | 0 |
| 4.6.3 | 1 | 9.3 | 27.8% | 0 | 1 |
| 4.6.2 | 1 | 9.3 | 27.8% | 0 | 1 |
| 4.6.1 | 1 | 9.3 | 27.8% | 0 | 1 |
| 4.5.7 | 1 | 9.3 | 27.8% | 0 | 1 |
| 4.5.6 | 2 | 9.7 | 15.3% | 0 | 1 |
| 4.5.5 | 2 | 9.7 | 15.3% | 0 | 1 |
| 4.5 | 4 | 7.6 | 13.5% | 0 | 1 |