CVE-2018-17445: Command Injection
A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17445?
The severity of CVE-2018-17445 is critical, with a severity value of 9.8.
Which software versions are affected by CVE-2018-17445?
Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4 are affected by CVE-2018-17445.
What is the CWE category of CVE-2018-17445?
The CWE category of CVE-2018-17445 is CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')).
How can I fix the Command Injection issue in Citrix SD-WAN and NetScaler SD-WAN?
To fix the Command Injection issue in Citrix SD-WAN and NetScaler SD-WAN, it is recommended to update to version 9.3.6 or later for NetScaler SD-WAN and version 10.0.4 or later for Citrix SD-WAN.
Where can I find more information about CVE-2018-17445?
More information about CVE-2018-17445 can be found at the following references: http://www.securityfocus.com/bid/105711, https://support.citrix.com/article/CTX236992.