Vulnerabilities > CVE-2007-6192 - Cryptographic Issues vulnerability in Citrix Netscaler 8.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-plaintext attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Signature Spoofing by Key Recreation An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Nessus
NASL family | Web Servers |
NASL id | NETSCALER_WEB_COOKIE_CRYPTO.NASL |
description | The version of the Citrix NetScaler web management interface on the remote host uses weak encryption for protecting the HTTP cookie content by XORing sensitive values, including the username and password, with a fixed key stream. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 29220 |
published | 2007-12-06 |
reporter | This script is Copyright (c) 2007-2018 nnposter |
source | https://www.tenable.com/plugins/nessus/29220 |
title | NetScaler Web Management Interface Cookie Credentials Encryption Weakness |