9
CVSSv2

CVE-2018-6186

Published: 01/02/2018 Updated: 03/03/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

citrix netscaler 12.0

Vendor Advisories

Description of Problem A number of vulnerabilities have been identified in supported versions of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway The following vulnerabilities have been addressed: CVE-2018-6810: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway Directory Traversal Vulnerabilit ...