Citrix NetScaler ADC
cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:*:*:*:*:*:*:*, +2 more
- < 14.1-66.59
- < 13.1-62.23
- < 13.1-37.262
This vulnerability is being actively exploited in the wild.
A vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway when configured as a SAML Identity Provider. This vulnerability is due to insufficient input validation, which can lead to a memory overread condition.
Exploitation of this vulnerability causes a memory overread, which can potentially lead to information disclosure.
Affected customers are advised to upgrade to NetScaler ADC and NetScaler Gateway versions 14.1-66.59 or later, 13.1-62.23 or later, or for NetScaler ADC 13.1-FIPS and 13.1-NDcPP, version 13.1.37.262 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.