First published: Mon Mar 10 2014(Updated: )
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Application Delivery Controller Firmware | =9.3\(1\) | |
Citrix Application Delivery Controller Firmware | =9.3.e | |
Citrix Application Delivery Controller Firmware | =10.0 | |
Citrix Application Delivery Controller Firmware | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6943 is rated as High severity due to its potential for exploitation through LDAP injection.
To mitigate CVE-2013-6943, upgrade to Citrix NetScaler ADC versions 9.3-64.4, 10.0-77.5, or 10.1-118.7 or later.
CVE-2013-6943 affects Citrix NetScaler Application Delivery Controller firmware versions 9.3.x, 10.0, and 10.1 prior to their respective fixed releases.
CVE-2013-6943 allows remote attackers to conduct LDAP injection attacks potentially compromising sensitive data.
While the best solution is to update the firmware, temporarily minimizing SSH and Web management access can help reduce exposure.