PT-2018-16891 · Citrix · Citrix Netscaler Gateway+3

Publicado

2018-03-01

·

Atualizado

2019-10-03

·

CVE-2018-5314

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Citrix NetScaler ADC and NetScaler Gateway versions 11.0 before build 70.16 Citrix NetScaler ADC and NetScaler Gateway versions 11.1 before build 55.13 Citrix NetScaler ADC and NetScaler Gateway versions 12.0 before build 53.13 NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.0
Description The issue allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt. This is a command injection vulnerability.
Recommendations For Citrix NetScaler ADC and NetScaler Gateway versions 11.0 before build 70.16, update to build 70.16 or later. For Citrix NetScaler ADC and NetScaler Gateway versions 11.1 before build 55.13, update to build 55.13 or later. For Citrix NetScaler ADC and NetScaler Gateway versions 12.0 before build 53.13, update to build 53.13 or later. For NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.0, consider disabling SSH login until a patch is available.

Correção

RCE

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5314

Produtos afetados

Citrix Netscaler Adc
Citrix Netscaler Gateway
Netscaler Load Balancing
Netscaler Sd-Wan/Cloudbridge