CVE-2016-9028: High severity citrix application delivery controller firmware vulnerability
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9028?
CVE-2016-9028 has a high severity rating as it allows remote attackers to steal session cookies, leading to unauthorized access.
How do I fix CVE-2016-9028?
To fix CVE-2016-9028, upgrade Citrix NetScaler ADC to the recommended versions or later as specified by the vendor's advisory.
Which versions of Citrix NetScaler ADC are affected by CVE-2016-9028?
CVE-2016-9028 affects Citrix NetScaler ADC versions before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F, and 11.1 47.14.
What type of attack does CVE-2016-9028 enable?
CVE-2016-9028 enables an unauthorized redirect attack which can lead to session cookie theft for legitimate users.
What are the potential consequences of CVE-2016-9028?
The consequences of CVE-2016-9028 include unauthorized access to sensitive information and user sessions, which can compromise user accounts.