PT-2018-16891 · Citrix · Citrix Netscaler Gateway+3

Published

2018-03-01

·

Updated

2019-10-03

·

CVE-2018-5314

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Citrix NetScaler ADC and NetScaler Gateway versions 11.0 before build 70.16 Citrix NetScaler ADC and NetScaler Gateway versions 11.1 before build 55.13 Citrix NetScaler ADC and NetScaler Gateway versions 12.0 before build 53.13 NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.0
Description The issue allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt. This is a command injection vulnerability.
Recommendations For Citrix NetScaler ADC and NetScaler Gateway versions 11.0 before build 70.16, update to build 70.16 or later. For Citrix NetScaler ADC and NetScaler Gateway versions 11.1 before build 55.13, update to build 55.13 or later. For Citrix NetScaler ADC and NetScaler Gateway versions 12.0 before build 53.13, update to build 53.13 or later. For NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.0, consider disabling SSH login until a patch is available.

Fix

RCE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5314

Affected Products

Citrix Netscaler Adc
Citrix Netscaler Gateway
Netscaler Load Balancing
Netscaler Sd-Wan/Cloudbridge