CVE-2018-5314
Last modified
CVE-2018-5314 is a vulnerability of currently unknown severity. Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.. EPSS estimates a 2.91% chance of exploitation in the next 30 days.
Description
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Netscaler Application Delivery Controller | 11.0 |
| Citrix | Netscaler Application Delivery Controller | 11.1 |
| Citrix | Netscaler Application Delivery Controller | 12.0 |
| Citrix | Netscaler Gateway | 11.0 |
| Citrix | Netscaler Gateway | 11.1 |
| Citrix | Netscaler Gateway | 12.0 |
| Citrix | Netscaler Sd-Wan | 9.3.0 |
References
- http://www.securityfocus.com/bid/103186Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040439Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX232199Vendor Advisory
- http://www.securityfocus.com/bid/103186Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040439Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX232199Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5314?
How severe is CVE-2018-5314?
How do I fix CVE-2018-5314?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5308PoDoFo 0.9.5 does not properly validate memcpy arguments in …
- CVE-2018-5309In PoDoFo 0.9.5, there is an integer overflow in the PdfObje…
- CVE-2018-5310In the "Media from FTP" plugin before 9.85 for WordPress, Di…
- CVE-2018-5311The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has …
- CVE-2018-5312The tabs-responsive plugin 1.8.0 for WordPress has XSS via t…
- CVE-2018-5313A vulnerability allows local attackers to escalate privilege…
- CVE-2018-5315The Wachipi WP Events Calendar plugin 1.0 for WordPress has …
- CVE-2018-5316The "SagePay Server Gateway for WooCommerce" plugin before 1…
- CVE-2018-5319RAVPower FileHub 2.000.056 allows remote users to steal sens…
- CVE-2018-5326Cheetah Mobile CM Browser 5.22.06.0012, when installed on un…
- CVE-2018-5327Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, wh…
- CVE-2018-5328ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to var…
Are you affected by CVE-2018-5314?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
