CVE-2016-2072: Medium severity netscaler adc vulnerability
The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2072?
CVE-2016-2072 is classified as a medium-security vulnerability due to its potential for clickjacking attacks.
How do I fix CVE-2016-2072?
To remediate CVE-2016-2072, update to Citrix NetScaler Application Delivery Controller and NetScaler Gateway versions at or above the required builds which mitigate this vulnerability.
Who is affected by CVE-2016-2072?
CVE-2016-2072 affects Citrix NetScaler Application Delivery Controller versions 10.1, 10.5, and 11.0 prior to specified builds.
What types of attacks does CVE-2016-2072 enable?
CVE-2016-2072 enables remote attackers to perform clickjacking attacks, potentially compromising user interactions.
Is user interaction required to exploit CVE-2016-2072?
No, exploitation of CVE-2016-2072 can occur without direct user interaction, making it particularly concerning.