LiveActive security incident?Get immediate response
CVE Record

CVE-2021-22920: A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (for...

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This Citrix issue could let an attacker use a SAML authentication hijack in a phishing scenario to steal a valid user session. The business risk is unauthorized access through compromised sessions, especially where Citrix Gateway or ADC fronts remote access or sensitive applications.

Executive priority

Treat this as a near-term remote-access identity risk, not a generic infrastructure bug. Prioritize validation where Citrix provides access to internal applications or VPN-like services.

Technical view

CVE-2021-22920 affects Citrix ADC, Citrix Gateway, and specified Citrix SD-WAN WANOP appliances. The source describes improper access control leading to SAML authentication hijack and session theft. No CVSS score, exploit status, or detailed remediation steps are provided in the bundle.

Likely exposure

Organizations using Citrix ADC, Citrix Gateway, or Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, or 5100-WO may be exposed, particularly if SAML authentication is enabled.

Exploitation context

The provided sources describe phishing-enabled SAML authentication hijack and session theft. They do not state active exploitation, and the CVE is not listed as CISA KEV in the bundle.

Researcher notes

Evidence is limited: the bundle names products, versions, CWE-284, and SAML session-theft impact, but provides no CVSS, proof-of-concept status, or explicit fix text. Avoid claims beyond Citrix and CVE records.

Mitigation direction

  • Review Citrix advisory CTX319135 for vendor-approved remediation guidance.
  • Inventory Citrix ADC, Gateway, and named SD-WAN WANOP deployments.
  • Prioritize systems using SAML authentication for review.
  • Check vendor guidance before assuming a fixed build or workaround.
  • Monitor Citrix authentication logs for unusual SAML session activity.

Validation and detection

  • Confirm whether affected Citrix products are deployed.
  • Identify appliance versions and compare them with Citrix advisory CTX319135.
  • Determine whether SAML authentication is configured on exposed services.
  • Review recent authentication logs for suspicious session creation or reuse.
  • Verify remediation status through vendor-supported version or configuration evidence.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-22920 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aCitrix ADC, Citrix GatewayCitrix ADC and Citrix Gateway 13.0-82.45 and later releases of 13.0, Citrix ADC and Citrix Gateway 12.1-62.27 and later releases of 12.1Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.