CVE-2018-5314
Last modified
CVE-2018-5314 is a vulnerability of currently unknown severity. Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.. EPSS estimates a 2.91% chance of exploitation in the next 30 days.
Description
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Netscaler Application Delivery Controller | 11.0 |
| Citrix | Netscaler Application Delivery Controller | 11.1 |
| Citrix | Netscaler Application Delivery Controller | 12.0 |
| Citrix | Netscaler Gateway | 11.0 |
| Citrix | Netscaler Gateway | 11.1 |
| Citrix | Netscaler Gateway | 12.0 |
| Citrix | Netscaler Sd-Wan | 9.3.0 |
References
- http://www.securityfocus.com/bid/103186Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040439Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX232199Vendor Advisory
- http://www.securityfocus.com/bid/103186Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040439Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX232199Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5314?
How severe is CVE-2018-5314?
How do I fix CVE-2018-5314?
Are you affected by CVE-2018-5314?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
