CVE-2017-5933: Infoleak
Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5933?
CVE-2017-5933 is considered a medium severity vulnerability due to its potential impact on GCM nonce management.
How do I fix CVE-2017-5933?
To fix CVE-2017-5933, upgrade Citrix NetScaler ADC and NetScaler Gateway to versions that include patches for this vulnerability.
What versions are affected by CVE-2017-5933?
CVE-2017-5933 affects Citrix NetScaler ADC and NetScaler Gateway versions 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21.
What impact does CVE-2017-5933 have?
CVE-2017-5933 may allow remote attackers to obtain GCM authentication keys and spoof data due to nonce reuse.
Is there a workaround for CVE-2017-5933?
There are no specific workarounds for CVE-2017-5933; applying the recommended updates is the best mitigation strategy.