CVE-2013-6940: Medium severity Citrix Netscaler Application Delivery Controller Firmware vulnerability
Published Mar 10, 2014
·Updated
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecified vectors.
Affected Software
4 affected components
Citrix Netscaler Application Delivery Controller Firmware=9.3\(1\)
Citrix Netscaler Application Delivery Controller Firmware=9.3.e
Citrix Netscaler Application Delivery Controller Firmware=10.0
Citrix Netscaler Application Delivery Controller Firmware=10.1
Event History
Mar 10, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Mar 11, 2014
Data Sourced
via NVD·01:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6940?
CVE-2013-6940 has a severity rating that indicates a potential risk of information disclosure.
2
How do I fix CVE-2013-6940?
To fix CVE-2013-6940, update to the latest firmware versions 9.3-64.4, 10.0-77.5, or 10.1-118.7.
3
What software versions are affected by CVE-2013-6940?
CVE-2013-6940 affects Citrix NetScaler Application Delivery Controller versions 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7.
4
What type of information can be leaked due to CVE-2013-6940?
CVE-2013-6940 can leak sensitive user credentials due to improper logging.
5
Is authentication affected by CVE-2013-6940?
Yes, CVE-2013-6940 impacts authentication by potentially exposing user credentials to attackers.