First published: Fri Nov 30 2007(Updated: )
The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being used by the web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler SD-WAN | =8.0-build_47.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6193 has been classified as a medium severity vulnerability due to the potential exposure of sensitive network configuration information.
To address CVE-2007-6193, it is recommended to upgrade to a patched version of Citrix NetScaler that does not use cookies to store sensitive information.
CVE-2007-6193 exploits the web management interface of Citrix NetScaler by storing the primary IP address in a cookie, potentially allowing access to sensitive data.
CVE-2007-6193 affects users of Citrix NetScaler version 8.0 build 47.8 that have implemented the web management interface.
Preventing CVE-2007-6193 involves disabling the cookie that stores the device's primary IP address or minimizing the exposure of the web management interface.