CVE-2018-6186: SSRF
Published Feb 1, 2018
·Updated
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/readurl URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.
Affected Software
1 affected component
Citrix NetScaler=12.0
Event History
Feb 1, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-6186?
CVE-2018-6186 is a vulnerability that allows an SSRF attack via the /rapi/read_url URI in Citrix NetScaler VPX through NS12.0 53.13.nc.
2
How severe is CVE-2018-6186?
The severity of CVE-2018-6186 is critical with a severity score of 8.8.
3
What software is affected by CVE-2018-6186?
Citrix NetScaler VPX version 12.0 is affected by CVE-2018-6186.
4
How can an attacker exploit CVE-2018-6186?
An authenticated attacker with a webapp account can exploit CVE-2018-6186 to perform an SSRF attack and gain access to the nsroot account.
5
Are there any references for CVE-2018-6186?
Yes, you can find references for CVE-2018-6186 at the following links: [LINK]