CVE-2017-14602

HIGH

Citrix NetScaler <11.1.55.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build 41.24) that, if exploited, could allow an attacker with access to the NetScaler management interface to gain administrative access to the appliance.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX228091
Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX227928
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100980

Scores

CVSS v3 7.2
EPSS 0.0039
EPSS Percentile 60.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (12)
citrix/application_delivery_controller_firmware 10.1
citrix/application_delivery_controller_firmware 10.5
citrix/application_delivery_controller_firmware 10.5e
citrix/application_delivery_controller_firmware 11.0
citrix/application_delivery_controller_firmware 11.1
citrix/application_delivery_controller_firmware 12.0
citrix/netscaler_gateway_firmware 10.1
citrix/netscaler_gateway_firmware 10.5
citrix/netscaler_gateway_firmware 10.5e
citrix/netscaler_gateway_firmware 11.0
... and 2 more
Published Sep 26, 2017
Tracked Since Feb 18, 2026