#VU9683 Information disclosure in Citrix NetScaler - CVE-2017-17549 

 

#VU9683 Information disclosure in Citrix NetScaler - CVE-2017-17549

Published: December 19, 2017


Vulnerability identifier: #VU9683
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-17549
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Citrix NetScaler
Software vendor:
Citrix

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists on systems using TLS with client certificates enabled and Diffie-Hellman Ephemeral (DHE) key exchange due to unspecified error. A remote attacker can obtain cleartext traffic from the backend client TLS handshake.

Remediation

Update to version 10.5 build 67.13, 11.0 build 71.22, 11.1 build 56.19, 12.0 build 53.22 or later.

External links