9.8
CVSSv3

CVE-2019-18225

Published: 21/10/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Citrix Application Delivery Controller (ADC) and Gateway prior to 10.5 build 70.8, 11.x prior to 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance administrative access. These products formerly used the NetScaler brand name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citrix application_delivery_controller_firmware 12.0

citrix application_delivery_controller_firmware 12.1

citrix application_delivery_controller_firmware 13.0

citrix application_delivery_controller_firmware 10.5

citrix application_delivery_controller_firmware 11.1

citrix netscaler_gateway_firmware 11.1

citrix netscaler_gateway_firmware 10.5

citrix netscaler_gateway_firmware 12.0

citrix netscaler_gateway_firmware 12.1

citrix gateway_firmware 13.0

Vendor Advisories

Description of Problem A vulnerability has been identified in the management interface of Citrix Application Delivery Controller (ADC) formerly known as NetScaler ADC, and Citrix Gateway, formerly known as NetScaler Gateway, that, if exploited, could allow an attacker with access to the management interface to gain administrative access to the appl ...