CVE-2023-24487
Arbitrary file read in Citrix ADC and Citrix Gateway
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 22.38%
- CWE
- CWE-253
- Published
- 2023-07-10
- Last modified
- 2026-03-13
Affected products
- Citrix Citrix ADC and Citrix Gateway
- Citrix Citrix ADC and Citrix Gateway
- Citrix Citrix ADC and Citrix Gateway
- Citrix Citrix ADC and Citrix Gateway
- Citrix Citrix ADC and Citrix Gateway
- Citrix Citrix ADC and Citrix Gateway
Weakness type
Related vulnerabilities
- CVE-2023-49286 — Denial of Service in Helper Process management
- CVE-2023-4501 — Authentication bypass in OpenText (Micro Focus) Enterprise Server
- CVE-2026-0648 — The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_
- CVE-2025-57767 — Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
- CVE-2024-1622 — Routinator terminates when RTR connection is reset too quickly after opening
- CVE-2021-37625 — Incorrect Check of Function Return Value in Skytable
- CVE-2026-35091 — Corosync: corosync: denial of service and information disclosure via crafted udp packet
- CVE-2024-32475 — Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes