Citrix
Citrix Netscaler: vulnerabilidades y CVE
Citrix Netscaler tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-6186 | Alta (8.8) | 3.1% | — | 1 feb 2018 | Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote… |
| CVE-2016-2072 | Media (6.1) | 1.1% | — | 17 feb 2016 | The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows… |
| CVE-2016-2071 | Crítica (9.8) | 3.4% | — | 17 feb 2016 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via… |
| CVE-2015-2841 | Media (5) | 5.5% | — | 3 abr 2015 | Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml… |
| CVE-2015-2840 | Media (4.3) | 1.9% | — | 3 abr 2015 | Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter. |
| CVE-2015-2839 | Media (4.3) | 2.0% | — | 3 abr 2015 | The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name… |
| CVE-2015-2838 | Media (6.8) | 2.9% | — | 3 abr 2015 | Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary… |
| CVE-2007-6192 | Media (4.3) | 0.70% | — | 30 nov 2007 | The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext… |
| CVE-2007-6193 | Media (5) | 1.1% | — | 30 nov 2007 | The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this… |
| CVE-2007-6037 | Media (4.3) | 3.6% | — | 20 nov 2007 | Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified… |
📰 Noticias relacionadas
Otros productos de Citrix
Xenserver · 55Netscaler Gateway · 45Netscaler Application Delivery Controller · 39Netscaler Gateway Firmware · 31Application Delivery Controller Firmware · 30Netscaler Application Delivery Controller Firmware · 29Xenmobile Server · 22Gateway · 19Sd-wan · 18Netscaler Sd-wan · 16Gateway Firmware · 15Access Gateway · 14