CVE-2018-5314 – Authentication Bypass Vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway

This vulnerability has been addressed in the following versions of Citrix NetScaler ADC and NetScaler Gateway:

  • Citrix NetScaler ADC and NetScaler Gateway version 12.0 build 53.13 and later
  • Citrix NetScaler ADC and NetScaler Gateway version 11.1 build 55.13 and later
  • Citrix NetScaler ADC and NetScaler Gateway version 11.0 build 70.16 and later
  • Citrix NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition version 9.3.1 and later

Citrix recommends that customers impacted by this vulnerability upgrade to a version of the Citrix NetScaler ADC, NetScaler Gateway and NetScaler SD-WAN/Cloudbridge that contains a fix for this issue as soon as possible.

These versions are available on the Citrix website at the following addresses:

https://www.citrix.com/downloads/netscaler-adc/

https://www.citrix.com/downloads/netscaler-gateway/

https://www.citrix.com/downloads/netscaler-sd-wan/

In line with industry best practice, Citrix also recommends that customers limit access to the management interface to trusted traffic only. Citrix has published additional guidance on the secure configuration of NetScaler management interfaces. This can be found at the following location:

https://support.citrix.com/article/CTX228148

Related:

  • No Related Posts

Leave a Reply