CVE-2017-17549: Infoleak
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client Certificates and a Diffie-Hellman Ephemeral (DHE) key exchange.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Citrix NetScaler ADC and NetScaler Gateway vulnerability?
The vulnerability ID for this Citrix NetScaler ADC and NetScaler Gateway vulnerability is CVE-2017-17549.
What is the severity level of CVE-2017-17549?
The severity level of CVE-2017-17549 is medium with a severity value of 5.9.
Which versions of Citrix NetScaler ADC and NetScaler Gateway are affected by CVE-2017-17549?
Citrix NetScaler ADC and NetScaler Gateway versions 10.5, 11.0, 11.1, and 12.0 are affected by CVE-2017-17549.
How can remote attackers exploit CVE-2017-17549?
Remote attackers can exploit CVE-2017-17549 by obtaining sensitive information from the backend client TLS handshake through the use of TLS wi.
Is there a fix available for CVE-2017-17549?
Yes, there is a fix available for CVE-2017-17549. You can find more information on the Citrix support website.