CVE-2014-4347: Citrix NetScaler Access Gateway

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.

Affected products

  • Citrix NetScaler Access Gateway
  • Citrix NetScaler Access Gateway Firmware: version 9.3 only; version 10.1 only
  • Citrix NetScaler Application Delivery Controller
  • Citrix NetScaler Application Delivery Controller Firmware: version 9.3 only; version 10.1 only

Published 2014-07-16. Last modified 2026-06-17.