The bug is described as an out-of-bounds read issue affecting NetScaler appliances configured as SAML IDP and leading to memory disclosure. It was discovered in NetScaler’s XML parser, which did not terminate unquoted XML attribute values if they were followed by a newline character. Because of the flaw, the parser would read past the intended buffer, and NetScaler would return memory contents in the NSC_TASS cookie in an HTTP response.
| Vendor | Product | Versions |
|---|---|---|
| citrix | netscaler_application_delivery_controller | 14.1, 13.1, 14.1 FIPs, 13.1 FIPS and NDcPP, 14.1, 13.1, 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS, 13.1-37.272 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| citrix | netscaler | cert_advisory | 90% |
| citrix | netscaler_gateway | cve_cpe | 95% |
Updated product to include NetScaler Gateway, added new affected versions and fixed version numbers, and included additional CVE tags.
Updated description with technical details about the out-of-bounds read issue and added information on active exploitation and related IP addresses.
Updated description with new details, added CVSS score of 8.8, and included new CWE ID CWE-20.
Updated severity to CRITICAL, changed exploit availability to false, and provided a more detailed description of the vulnerability.
Initial creation