CVE-2018-5314: Command Injection
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5314?
CVE-2018-5314 is a command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway before certain build versions.
How severe is CVE-2018-5314?
CVE-2018-5314 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-5314?
CVE-2018-5314 affects Citrix NetScaler ADC and NetScaler Gateway versions 11.0, 11.1, and 12.0, as well as NetScaler Load Balancing instances distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000, and 5100 WAN Optimization Edition 9.3.
How do I fix CVE-2018-5314?
To fix CVE-2018-5314, update your Citrix NetScaler ADC, NetScaler Gateway, and NetScaler Load Balancing instance to the recommended build versions listed in the Citrix advisory.
Where can I find more information about CVE-2018-5314?
You can find more information about CVE-2018-5314 in the following references: [SecurityFocus](http://www.securityfocus.com/bid/103186), [SecurityTracker](http://www.securitytracker.com/id/1040439), and the [Citrix advisory](https://support.citrix.com/article/CTX232199).