CVE Vulnerabilities

CVE-2017-14602

Improper Authentication

Published: Sep 26, 2017 | Modified: Oct 03, 2019
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build 41.24) that, if exploited, could allow an attacker with access to the NetScaler management interface to gain administrative access to the appliance.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Application_delivery_controller_firmware Citrix 10.1 (including) 10.1 (including)
Application_delivery_controller_firmware Citrix 10.5 (including) 10.5 (including)
Application_delivery_controller_firmware Citrix 10.5e (including) 10.5e (including)
Application_delivery_controller_firmware Citrix 11.0 (including) 11.0 (including)
Application_delivery_controller_firmware Citrix 11.1 (including) 11.1 (including)
Application_delivery_controller_firmware Citrix 12.0 (including) 12.0 (including)
Netscaler_gateway_firmware Citrix 10.1 (including) 10.1 (including)
Netscaler_gateway_firmware Citrix 10.5 (including) 10.5 (including)
Netscaler_gateway_firmware Citrix 10.5e (including) 10.5e (including)
Netscaler_gateway_firmware Citrix 11.0 (including) 11.0 (including)
Netscaler_gateway_firmware Citrix 11.1 (including) 11.1 (including)
Netscaler_gateway_firmware Citrix 12.0 (including) 12.0 (including)

Potential Mitigations

References