First published: Wed Jul 16 2014(Updated: )
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler Access Gateway Firmware | =9.3 | |
Citrix NetScaler Access Gateway Firmware | =10.1 | |
Citrix NetScaler Access Gateway Firmware | ||
Citrix Application Delivery Controller Firmware | =9.3 | |
Citrix Application Delivery Controller Firmware | =10.1 | |
Citrix NetScaler ADC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4347 is considered a medium severity vulnerability.
To fix CVE-2014-4347, upgrade to Citrix NetScaler Application Delivery Controller and NetScaler Gateway versions 9.3-62.4 or 10.1-126.12 or later.
CVE-2014-4347 could allow attackers to access sensitive information by exploiting vulnerabilities related to cookie management.
CVE-2014-4347 affects Citrix NetScaler Application Delivery Controller and NetScaler Gateway versions prior to 9.3-62.4 and 10.1-126.12.
You can verify if your system is vulnerable to CVE-2014-4347 by checking the version of Citrix NetScaler software installed on your system.