CVE-2019-18225
Summary
| CVE | CVE-2019-18225 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-21 18:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance administrative access. These products formerly used the NetScaler brand name. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Citrix | Application Delivery Controller | - | All | All | All |
| Hardware | Citrix | Application Delivery Controller | - | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 10.5 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 11.1 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 12.0 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 12.1 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 13.0 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 10.5 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 11.1 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 12.0 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 12.1 | All | All | All |
| Operating System | Citrix | Application Delivery Controller Firmware | 13.0 | All | All | All |
| Hardware | Citrix | Gateway | - | All | All | All |
| Hardware | Citrix | Gateway | - | All | All | All |
| Operating System | Citrix | Gateway Firmware | 13.0 | All | All | All |
| Operating System | Citrix | Gateway Firmware | 13.0 | All | All | All |
| Hardware | Citrix | Netscaler Gateway | - | All | All | All |
| Hardware | Citrix | Netscaler Gateway | - | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 10.5 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 11.1 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 12.0 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 12.1 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 10.5 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 11.1 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 12.0 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 12.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Authentication Bypass Vulnerability in the Management Interface of Citrix Application Delivery Controller and Citrix Gateway | MISC | support.citrix.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.