Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 🔴 Critical: Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

🔴 Critical: Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
citrix
1 Posts 1 Posters 7 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Citrix has shipped security updates for NetScaler ADC and NetScaler Gateway deployments, addressing two vulnerabilities, including a critical-severity authentication bypass flaw. The issues impact customer-managed instances of these appliances, as well as certain FIPS and NDcPP builds, and the SecurAccess product.

    The most severe of the two vulnerabilities allows an attacker to bypass authentication on affected gateway and AAA server configurations. Successful exploitation could grant unauthorized access to the management interface or allow an attacker to impersonate legitimate users, depending on the deployment setup.

    All organizations running affected versions are advised to review the advisory and apply the relevant updates immediately. Given the public availability of proof-of-concept research in similar cases, prompt patching is strongly recommended.

    • Affected products: NetScaler ADC and NetScaler Gateway (customer-managed), including specific FIPS and NDcPP builds, and SecurAccess
    • Action required: Apply the latest vendor-provided updates to close the vulnerability path
    • Recommendation: If immediate patching is not possible, restrict management access to trusted networks and monitor for anomalous authentication activity

    Source: The Hacker News

    Is your team running any of the affected NetScaler builds, and are you prioritizing this patch ahead of your next maintenance window?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World