Vulnerabilities > CVE-2013-6940 - Credentials Management vulnerability in Citrix Netscaler Application Delivery Controller Firmware
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 4 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Misc. |
NASL id | CITRIX_NETSCALER_ADC_MULTIPLE.NASL |
description | The remote Citrix NetScaler version is affected by multiple vulnerabilities : - A denial of service vulnerability in the VM Virtual Machine Daemon. Please note that this particular vulnerability does not apply to Citrix NetScaler 10.1. (CVE-2013-6938) - A denial of service vulnerability in the Application Delivery Controller RADIUS authentication. (CVE-2013-6939) - An authenticated denial of service in the SNMP daemon. (CVE-2012-2142) - An unspecified authentication disclosure in the Application Delivery Controller. (CVE-2013-6940) - An unspecified shell breakout in the Application Delivery Controller firmware. (CVE-2013-6941) - An unspecified LDAP username injection vulnerability in the Application Delivery Controller. (CVE-2013-6943) - A cross-site scripting vulnerability in the AAA TM vServer user interface. (CVE-2013-6944) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 73205 |
published | 2014-03-26 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/73205 |
title | Citrix NetScaler Application Delivery Controller Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 66020 CVE(CAN) ID: CVE-2013-6940 Citrix NetScaler是一款网络流量管理产品。 Citrix NetScaler SDX 10.0及9.3版本的应用支付控制器在实现上存在安全漏洞,攻击者可利用此漏洞将用户凭证记录到磁盘,导致信息泄露。 0 Citrix NetScaler SDX 9.x Citrix NetScaler SDX 10.x 厂商补丁: Citrix ------ Citrix已经为此发布了一个安全公告(CTX139049)以及相应补丁: CTX139049:Citrix NetScaler Application Delivery Controller Multiple Security Vulnerabilities 链接:http://support.citrix.com/article/CTX139049 |
id | SSV:61744 |
last seen | 2017-11-19 |
modified | 2014-03-12 |
published | 2014-03-12 |
reporter | Root |
title | Citrix NetScaler应用交付控制器本地信息泄露漏洞(CVE-2013-6940) |