
Citrix Netscaler ADC and Gateway plagued by serious DOS and Open Redirect flaw
Redazione RHC : 9 July 2024 14:21
Two vulnerabilities have been identified in NetScaler ADC and NetScaler Gateway. Affected Versions: The following supported versions of NetScaler ADC and NetScaler Gateway are vulnerable:
These devices are widely used to enhance application performance and ensure controlled and secure access to sensitive data.
- NetScaler ADC and NetScaler Gateway 14.1 before version 14.1-25.53
- NetScaler ADC and NetScaler Gateway 13.1 before version 13.1-53.17
- NetScaler ADC and NetScaler Gateway 13.0 before version 13.0-92.31
- NetScaler ADC 13.1-FIPS before version 13.1-37.183
- NetScaler ADC 12.1-FIPS before version 12.1-55.304
- NetScaler ADC 12.1-NDcPP before version 12.1-55.304
Note: Version 12.1 of NetScaler ADC and NetScaler Gateway is now End Of Life (EOL) and therefore vulnerable. Customers are advised to upgrade their devices to supported versions.
Iscriviti GRATIS ai WorkShop Hands-On della RHC Conference 2025 (Giovedì 8 maggio 2025)
Il giorno giovedì 8 maggio 2025 presso il teatro Italia di Roma (a due passi dalla stazione termini e dalla metro B di Piazza Bologna), si terranno i workshop "hands-on", creati per far avvicinare i ragazzi alla sicurezza informatica e alla tecnologia. Questo anno i workshop saranno:
Creare Un Sistema Ai Di Visual Object Tracking (Hands on)
Social Engineering 2.0: Alla Scoperta Delle Minacce DeepFake
Doxing Con Langflow: Stiamo Costruendo La Fine Della Privacy?
Come Hackerare Un Sito WordPress (Hands on)
Il Cyberbullismo Tra Virtuale E Reale
Come Entrare Nel Dark Web In Sicurezza (Hands on)
Potete
iscrivervi gratuitamente all'evento, che è stato creato per poter ispirare i ragazzi verso la sicurezza informatica e la tecnologia.
Per ulteriori informazioni, scrivi a
[email protected] oppure su Whatsapp al
379 163 8765
Supporta RHC attraverso:
Ti piacciono gli articoli di Red Hot Cyber? Non aspettare oltre, iscriviti alla newsletter settimanale per non perdere nessun articolo.
Vulnerability Summary: NetScaler ADC and NetScaler Gateway have the following vulnerabilities:
- CVE-2024-5491: Denial of Service vulnerability affecting ADC or Gateway appliances configured with SNMP (NSIP/SNIP).
- CWE: Improper restriction of operations within the bounds of a memory buffer
- CVSS v4.0 Base Score: 7.1
- CVE-2024-5492: Open redirect vulnerability allowing a remote, unauthenticated attacker to redirect users to arbitrary websites.
- CWE: URL redirection to untrusted sites (‘Open Redirect’)
- CVSS v4.0 Base Score: 5.1
Recommended Actions for Customers: Cloud Software Group strongly advises affected customers of NetScaler ADC and NetScaler Gateway to immediately install the relevant updated versions:
- NetScaler ADC and NetScaler Gateway version 14.1-25.53 and later
- NetScaler ADC and NetScaler Gateway version 13.1-53.17 and later for 13.1
- NetScaler ADC and NetScaler Gateway version 13.0-92.31 and later for 13.0
- NetScaler ADC version 13.1-FIPS 13.1-37.183 and later
- NetScaler ADC version 12.1-FIPS 12.1-55.304 and later
- NetScaler ADC version 12.1-NDcPP 12.1-55.304 and later
Cloud Software Group would like to express gratitude to Nanyu Zhong of VARAS@IIE and Mauro Dini for their valuable contributions in ensuring the security of Citrix customers.
Meanwhile, Citrix is actively informing its customers and partners about these critical security issues through a bulletin published on the Citrix Knowledge Center, accessible at the following address: https://support.citrix.com/securitybulletins.
RedazioneThe editorial team of Red Hot Cyber consists of a group of individuals and anonymous sources who actively collaborate to provide early information and news on cybersecurity and computing in general.