CVE-2019-6485
Last modified
CVE-2019-6485 is a vulnerability of currently unknown severity. Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Netscaler Gateway Firmware | 10.5 |
| Citrix | Netscaler Gateway Firmware | 11.0 |
| Citrix | Netscaler Gateway Firmware | 11.1 |
| Citrix | Netscaler Gateway Firmware | 12.0 |
| Citrix | Netscaler Gateway Firmware | 12.1 |
| Citrix | Netscaler Application Delivery Controller Firmware | 10.5 |
| Citrix | Netscaler Application Delivery Controller Firmware | 11.0 |
| Citrix | Netscaler Application Delivery Controller Firmware | 11.1 |
| Citrix | Netscaler Application Delivery Controller Firmware | 12.0 |
| Citrix | Netscaler Application Delivery Controller Firmware | 12.1 |
References
- http://www.securityfocus.com/bid/106783Third Party Advisory, VDB Entry
- https://github.com/RUB-NDS/TLS-Padding-OraclesProduct, Third Party Advisory
- https://support.citrix.com/article/CTX240139Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106783Third Party Advisory, VDB Entry
- https://github.com/RUB-NDS/TLS-Padding-OraclesProduct, Third Party Advisory
- https://support.citrix.com/article/CTX240139Mitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6485?
How severe is CVE-2019-6485?
How do I fix CVE-2019-6485?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6475Mirror zones are a BIND feature allowing recursive servers t…7.5
- CVE-2019-6476A defect in code added to support QNAME minimization can cau…7.5
- CVE-2019-6477With pipelining enabled each incoming query on a TCP connect…7.5
- CVE-2019-6478Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2019-6479Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2019-6481Abine Blur 7.8.2431 allows remote attackers to conduct "Seco…
- CVE-2019-6486Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 a…
- CVE-2019-6487TP-Link WDR Series devices through firmware v3 (such as TL-W…
- CVE-2019-6488The string component in the GNU C Library (aka glibc or libc…
- CVE-2019-6489Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices bef…
- CVE-2019-6491RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Inject…
- CVE-2019-6492SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never fr…
Are you affected by CVE-2019-6485?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
