CVE-2013-6944: Citrix NetScaler Application Delivery Controller Firmware

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

  • Citrix NetScaler Application Delivery Controller Firmware: version 9.3(1) only; version 9.3.e only; version 10.0 only; version 10.1 only

Published 2014-03-11. Last modified 2026-06-17.