PT-2019-18111 · Citrix · Citrix Netscaler Gateway+1

Published

2019-02-22

·

Updated

2020-08-24

·

CVE-2019-6485

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Citrix NetScaler Gateway versions 10.5 through 12.1 before build 50.31 Citrix Application Delivery Controller (ADC) versions 10.5 through 12.1 before build 50.31
Description The issue allows remote attackers to obtain sensitive plaintext information due to a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.
Recommendations For Citrix NetScaler Gateway versions 10.5 through 12.1 before build 50.31, update to build 50.31 or later. For Citrix Application Delivery Controller (ADC) versions 10.5 through 12.1 before build 50.31, update to build 50.31 or later.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6485

Affected Products

Citrix Application Delivery Controller
Citrix Netscaler Gateway