CVE-2019-6485
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before…
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327
- Affected
- citrix/netscaler gateway firmware · citrix/netscaler application delivery controller firmware
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/106783Third Party Advisory, VDB Entry
- https://github.com/RUB-NDS/TLS-Padding-OraclesProduct, Third Party Advisory
- https://support.citrix.com/article/CTX240139Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106783Third Party Advisory, VDB Entry
- https://github.com/RUB-NDS/TLS-Padding-OraclesProduct, Third Party Advisory
- https://support.citrix.com/article/CTX240139Mitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.