First published: Wed Jul 16 2014(Updated: )
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Application Delivery Controller Firmware | =10.1 | |
Citrix NetScaler ADC | ||
Citrix NetScaler Access Gateway Firmware | =10.1 | |
Citrix NetScaler Access Gateway Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4346 has a high severity due to its potential for remote code execution via XSS in the Citrix NetScaler administration interface.
To fix CVE-2014-4346, upgrade to a patched version of Citrix NetScaler Application Delivery Controller or NetScaler Gateway, specifically version 10.1-126.12 or later.
CVE-2014-4346 affects Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway versions prior to 10.1-126.12.
CVE-2014-4346 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
Yes, CVE-2014-4346 can be exploited remotely, allowing attackers to execute malicious scripts without physical access to the affected systems.