CVE-2019-18177: Citrix Application Delivery Controller Firmware

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

Affected products

  • Citrix Application Delivery Controller Firmware: before 13.0-58.30 (fixed in 13.0-58.30)
  • Citrix Gateway: before 13.0-58.30 (fixed in 13.0-58.30)

Published 2022-12-26. Last modified 2026-06-17.