CVE-2015-5080
Summary
| CVE | CVE-2015-5080 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-16 14:59:00 UTC |
| Updated | 2016-12-07 18:15:00 UTC |
| Description | The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to rapi/ipsec_logs. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix NetScaler ADC and Gateway CVE-2015-5080 Arbitrary Command Injection Vulnerability | BID | www.securityfocus.com | |
| CVE-2015-5080 - Vulnerability in Citrix NetScaler Application Deliver Controller and NetScaler Gateway Management Interface Could Result in Arbitrary Command Injection | CONFIRM | support.citrix.com | |
| Citrix NetScaler ADC and NetScaler Gateway Lets Remote Authenticated Users Execute Arbitrary Shell Commands - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Risks in POS Systems: The Importance of a Security Assessment | MISC | security-assessment.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.