CVE-2018-18517
UnknownEPSS 0.83%
Last modified
CVE-2018-18517 is a vulnerability of currently unknown severity. Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Netscaler Gateway Firmware | >= 10.5.0, < 10.5.69.003 |
| Citrix | Netscaler Gateway Firmware | >= 11.1.0, < 11.1.59.004 |
| Citrix | Netscaler Gateway Firmware | >= 12.0.0, < 12.0.58.7 |
| Citrix | Netscaler Gateway Firmware | >= 12.1.0, < 12.1.49.1 |
References
- http://www.securityfocus.com/bid/105725Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042023Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX239002Vendor Advisory
- http://www.securityfocus.com/bid/105725Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042023Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX239002Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18517?
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.
How severe is CVE-2018-18517?
Severity scoring for CVE-2018-18517 is pending analysis. The EPSS model estimates a 0.83% probability of exploitation in the next 30 days.
How do I fix CVE-2018-18517?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18511Cross-origin images can be read from a canvas element in vio…
- CVE-2018-18512A use-after-free vulnerability can occur while playing a sou…
- CVE-2018-18513A crash can occur when processing a crafted S/MIME message o…
- CVE-2018-18514Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-18515Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-18516Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-18519BestXsoftware Best Free Keylogger before 6.0.0 allows local …
- CVE-2018-18520An Invalid Memory Address Dereference exists in the function…6.5
- CVE-2018-18521Divide-by-zero vulnerabilities in the function arlib_add_sym…5.5
- CVE-2018-18524Evernote 6.15 on Windows has an incorrectly repaired stored …
- CVE-2018-18527OwnTicket 2018-05-23 allows SQL Injection via the showTicket…
- CVE-2018-18529ThinkPHP 3.2.4 has SQL Injection via the count parameter bec…
Are you affected by CVE-2018-18517?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
