CVE-2018-7218

CRITICAL

Citrix NetScaler <10.5.68.7-12.0.57.24 - RCE

Title source: llm
STIX 2.1

Description

The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX234869
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040921

Scores

CVSS v3 9.8
EPSS 0.0590
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (8)
citrix/application_delivery_controller_firmware 10.5
citrix/application_delivery_controller_firmware 11.0
citrix/application_delivery_controller_firmware 11.1
citrix/application_delivery_controller_firmware 12.0
citrix/netscaler_gateway_firmware 10.5
citrix/netscaler_gateway_firmware 11.0
citrix/netscaler_gateway_firmware 11.1
citrix/netscaler_gateway_firmware 12.0
Published May 17, 2018
Tracked Since Feb 18, 2026