CVE-2017-14602
moderate-risk
Published 2017-09-26
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build 41.24) that, if exploited, could allow an attacker with access to the NetScaler management interface to gain administrative access to the appliance.
Do I need to act?
-
0.39% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10
High
NETWORK
/ LOW complexity
Affected Products (12)
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/100980
Mitigation
https://support.citrix.com/article/CTX227928
Third Party Advisory
http://www.securityfocus.com/bid/100980
Mitigation
https://support.citrix.com/article/CTX227928
44
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
1/34 · Minimal
Exposure
17/34 · Moderate