Description
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access
CVSS breakdown
CVSS 4.0
Attack Vector
Adjacent
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
Low
Integrity (Subsequent System)
Low
Availability (Subsequent System)
Low
Affected products
- NetScaler / ADC14.1 – 47.48
- NetScaler / ADC13.1 – 59.22
- NetScaler / ADC13.1 FIPS and NDcPP – 37.241
- NetScaler / ADC12.1 FIPS and NDcPP – 55.330
- NetScaler / Gateway14.1 – 47.48
- NetScaler / Gateway13.1 – 59.22
- NetScaler / Gateway13.1 FIPS and NDcPP – 37.241
- NetScaler / Gateway12.1 FIPS and NDcPP – 55.330
Updated 30m ago · 2 sources