PT-2018-16891 · Citrix · Citrix Netscaler Gateway+3
Publicado
2018-03-01
·
Atualizado
2019-10-03
·
CVE-2018-5314
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Citrix NetScaler ADC and NetScaler Gateway versions 11.0 before build 70.16
Citrix NetScaler ADC and NetScaler Gateway versions 11.1 before build 55.13
Citrix NetScaler ADC and NetScaler Gateway versions 12.0 before build 53.13
NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.0
Description
The issue allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt. This is a command injection vulnerability.
Recommendations
For Citrix NetScaler ADC and NetScaler Gateway versions 11.0 before build 70.16, update to build 70.16 or later.
For Citrix NetScaler ADC and NetScaler Gateway versions 11.1 before build 55.13, update to build 55.13 or later.
For Citrix NetScaler ADC and NetScaler Gateway versions 12.0 before build 53.13, update to build 53.13 or later.
For NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.0, consider disabling SSH login until a patch is available.
Correção
RCE
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citrix Netscaler Adc
Citrix Netscaler Gateway
Netscaler Load Balancing
Netscaler Sd-Wan/Cloudbridge