ID

VAR-201803-2108


CVE

CVE-2018-6809


TITLE

Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-002543

DESCRIPTION

NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system. Citrix NetScaler ADC and NetScaler Gateway Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly known as Citrix Access Gateway Enterprise Edition) are both products of Citrix Systems. NetScaler ADC is a service and application delivery solution (application delivery controller); NetScaler Gateway is a secure remote access solution. Security vulnerabilities exist in Citrix NetScaler ADC and NetScaler Gateway. The following products and versions are affected: Citrix NetScaler ADC Release 10.5, Release 11.0, Release 11.1, Release 12.0; NetScaler Gateway Release 10.5, Release 11.0, Release 11.1, Release 12.0

Trust: 1.8

sources: NVD: CVE-2018-6809 // JVNDB: JVNDB-2018-002543 // VULHUB: VHN-136841 // VULMON: CVE-2018-6809

AFFECTED PRODUCTS

vendor:citrixmodel:netscaler application delivery controllerscope:eqversion:10.5

Trust: 2.4

vendor:citrixmodel:netscaler application delivery controllerscope:eqversion:11.0

Trust: 2.4

vendor:citrixmodel:netscaler application delivery controllerscope:eqversion:11.1

Trust: 2.4

vendor:citrixmodel:netscaler application delivery controllerscope:eqversion:12.0

Trust: 2.4

vendor:citrixmodel:netscaler gatewayscope:eqversion:10.5

Trust: 2.4

vendor:citrixmodel:netscaler gatewayscope:eqversion:11.0

Trust: 2.4

vendor:citrixmodel:netscaler gatewayscope:eqversion:11.1

Trust: 2.4

vendor:citrixmodel:netscaler gatewayscope:eqversion:12.0

Trust: 2.4

sources: JVNDB: JVNDB-2018-002543 // CNNVD: CNNVD-201803-147 // NVD: CVE-2018-6809

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-6809
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-6809
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201803-147
value: CRITICAL

Trust: 0.6

VULHUB: VHN-136841
value: HIGH

Trust: 0.1

VULMON: CVE-2018-6809
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-6809
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-136841
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-6809
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-136841 // VULMON: CVE-2018-6809 // JVNDB: JVNDB-2018-002543 // CNNVD: CNNVD-201803-147 // NVD: CVE-2018-6809

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-136841 // JVNDB: JVNDB-2018-002543 // NVD: CVE-2018-6809

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-147

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201803-147

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-002543

PATCH

title:CTX232161url:https://support.citrix.com/article/CTX232161

Trust: 0.8

title:Citrix NetScaler Application Delivery Controller and NetScaler Gateway Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=78921

Trust: 0.6

title:Citrix Security Bulletins: Citrix NetScaler Application Delivery Controller and NetScaler Gateway Multiple Security Updatesurl:https://vulmon.com/vendoradvisory?qidtp=citrix_security_bulletins&qid=cf8a157f0a34d7fb512f6c61c9c75a50

Trust: 0.1

sources: VULMON: CVE-2018-6809 // JVNDB: JVNDB-2018-002543 // CNNVD: CNNVD-201803-147

EXTERNAL IDS

db:NVDid:CVE-2018-6809

Trust: 2.6

db:SECTRACKid:1040440

Trust: 1.8

db:JVNDBid:JVNDB-2018-002543

Trust: 0.8

db:CNNVDid:CNNVD-201803-147

Trust: 0.7

db:VULHUBid:VHN-136841

Trust: 0.1

db:VULMONid:CVE-2018-6809

Trust: 0.1

sources: VULHUB: VHN-136841 // VULMON: CVE-2018-6809 // JVNDB: JVNDB-2018-002543 // CNNVD: CNNVD-201803-147 // NVD: CVE-2018-6809

REFERENCES

url:https://support.citrix.com/article/ctx232161

Trust: 1.9

url:http://www.securitytracker.com/id/1040440

Trust: 1.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-6809

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-6809

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-136841 // VULMON: CVE-2018-6809 // JVNDB: JVNDB-2018-002543 // CNNVD: CNNVD-201803-147 // NVD: CVE-2018-6809

SOURCES

db:VULHUBid:VHN-136841
db:VULMONid:CVE-2018-6809
db:JVNDBid:JVNDB-2018-002543
db:CNNVDid:CNNVD-201803-147
db:NVDid:CVE-2018-6809

LAST UPDATE DATE

2024-11-23T22:26:25.815000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-136841date:2019-10-03T00:00:00
db:VULMONid:CVE-2018-6809date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-002543date:2018-04-18T00:00:00
db:CNNVDid:CNNVD-201803-147date:2019-10-23T00:00:00
db:NVDid:CVE-2018-6809date:2024-11-21T04:11:14.047

SOURCES RELEASE DATE

db:VULHUBid:VHN-136841date:2018-03-06T00:00:00
db:VULMONid:CVE-2018-6809date:2018-03-06T00:00:00
db:JVNDBid:JVNDB-2018-002543date:2018-04-18T00:00:00
db:CNNVDid:CNNVD-201803-147date:2018-03-07T00:00:00
db:NVDid:CVE-2018-6809date:2018-03-06T20:29:01.127