CVE-2014-8580: Medium severity citrix application delivery controller firmware vulnerability
Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access "network resources" of other users via unknown vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8580?
CVE-2014-8580 has been assigned a moderate severity level due to the potential for unauthorized access to network resources.
How do I fix CVE-2014-8580?
To fix CVE-2014-8580, update your Citrix NetScaler Application Delivery Controller or Gateway to the respective patched versions mentioned in the advisory.
Which versions are affected by CVE-2014-8580?
CVE-2014-8580 affects multiple versions of Citrix NetScaler, specifically those prior to 10.5-52.11 for version 10.5 and 10.1-129.11 for version 10.1.
What types of configurations are vulnerable in CVE-2014-8580?
The vulnerability in CVE-2014-8580 arises from unspecified configurations that allow remote authenticated users to access other users' network resources.
Is there a workaround for CVE-2014-8580?
While the best solution is to update to a patched version, administrators can mitigate CVE-2014-8580 by reviewing and tightening access controls and configurations.