CVE-2013-2767
Last modified
CVE-2013-2767 is a vulnerability of currently unknown severity. Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.. EPSS estimates a 1.54% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Netscaler Access Gateway Firmware | <= 9.3.61.5 |
| Citrix | Netscaler Access Gateway Firmware | 9.1 |
| Citrix | Netscaler Access Gateway Firmware | 9.2 |
| Citrix | Netscaler Access Gateway Firmware | 9.3 |
| Citrix | Netscaler Access Gateway Firmware | 10.0 |
| Citrix | Netscaler Access Gateway Firmware | 10.0.74.4 |
| Citrix | Netscaler Access Gateway | All versions |
References
- http://support.citrix.com/article/ctx137238Vendor Advisory
- http://www.kb.cert.org/vuls/id/521612US Government Resource
- http://support.citrix.com/article/ctx137238Vendor Advisory
- http://www.kb.cert.org/vuls/id/521612US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2767?
How severe is CVE-2013-2767?
How do I fix CVE-2013-2767?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2761The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC mo…
- CVE-2013-2762The Schneider Electric Magelis XBT HMI controller has a defa…
- CVE-2013-2763The Schneider Electric M340 PLC modules allow remote attacke…
- CVE-2013-2764Secure Entry Server before 4.7.0 contains a URI Redirection …6.1
- CVE-2013-2765The ModSecurity module before 2.7.4 for the Apache HTTP Serv…
- CVE-2013-2766Cross-site scripting (XSS) vulnerability in Splunk Web in Sp…
- CVE-2013-2770The installation functionality in the Novell Kanaka componen…
- CVE-2013-2773Nitro PDF 8.5.0.26: A specially crafted DLL file can facilit…7.8
- CVE-2013-2776sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when …
- CVE-2013-2777sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_…
- CVE-2013-2778Cross-site request forgery (CSRF) vulnerability in addressbo…
- CVE-2013-2779Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3…
Are you affected by CVE-2013-2767?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
