{ "id": "CVE-2015-5080", "sourceIdentifier": "cve@mitre.org", "published": "2015-07-16T14:59:05.933", "lastModified": "2024-11-21T02:32:17.817", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to rapi/ipsec_logs." }, { "lang": "es", "value": "La interfaz de gesti\u00f3n en Citrix NetScaler Application Delivery Controller (ADC) y NetScaler Gateway 10.1 anterior a 10.1.132.8, 10.5 anterior a Build 56.15 y 10.5.e anterior a Build 56.1505.e, permite a usuarios remotos autenticados ejecutar comandos de shell arbitrarios a trav\u00e9s de metacaracteres de shell en el par\u00e1metro de filtro to rapi/ipsec_logs." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C", "baseScore": 9.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE" }, "baseSeverity": "HIGH", "exploitabilityScore": 8.0, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-77" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1:*:*:*:*:*:*:*", "matchCriteriaId": "FD151FA3-8B96-48AF-B908-C29EAE88EF5B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.120.1316.e:*:*:*:*:*:*:*", "matchCriteriaId": "C2CEF78D-8155-4C7C-A7BC-6AB2920FDE39" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.121:*:*:*:*:*:*:*", "matchCriteriaId": "4200E498-5730-446C-B17D-C73CD9DD23BE" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.122:*:*:*:*:*:*:*", "matchCriteriaId": "4920C74B-2C41-4074-B376-BC464B787973" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.123:*:*:*:*:*:*:*", "matchCriteriaId": "E0790595-B322-4203-AE1A-0DF4AB2AAD8D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.124:*:*:*:*:*:*:*", "matchCriteriaId": "EF19EAF4-EB35-4668-9973-3F952B446395" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.125:*:*:*:*:*:*:*", "matchCriteriaId": "6698AF1B-AF32-475A-9018-1F70A98F5577" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.126:*:*:*:*:*:*:*", "matchCriteriaId": "0E596AB3-2C82-4B5A-8613-F273DE9ADE79" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.127:*:*:*:*:*:*:*", "matchCriteriaId": "3121D097-0E4E-4664-BFFD-A19A1B32E060" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.128:*:*:*:*:*:*:*", "matchCriteriaId": "2AEDF8DB-B375-4313-8239-9725BF754DFF" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.1.129:*:*:*:*:*:*:*", "matchCriteriaId": "4E5E2D43-0DD4-436B-9D8D-857D906C7846" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.5:*:*:*:*:*:*:*", "matchCriteriaId": "D8C7525B-2A2D-43AF-8DA0-11FF28322337" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_application_delivery_controller_firmware:10.5e:*:*:*:*:*:*:*", "matchCriteriaId": "0EE0A709-2C34-495C-85F1-9DEE8DD58BE7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.120.1316.e:*:*:*:*:*:*:*", "matchCriteriaId": "065F4DB8-29E4-485C-BA7E-53CBDEEEB2D9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.121:*:*:*:*:*:*:*", "matchCriteriaId": "C0A4789A-A774-46AE-A11D-D5209F0475E1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.122:*:*:*:*:*:*:*", "matchCriteriaId": "F26ED266-19D1-47FE-89A0-FA738B220517" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.123:*:*:*:*:*:*:*", "matchCriteriaId": "4015CD17-11F7-4982-952C-EA2C9D1F31A8" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.124:*:*:*:*:*:*:*", "matchCriteriaId": "2161AD30-18C5-4DB2-BC80-66F7CED4F839" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.125:*:*:*:*:*:*:*", "matchCriteriaId": "CC1319D8-D77C-47B1-A201-2279730EF0C6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.126:*:*:*:*:*:*:*", "matchCriteriaId": "C6506EBE-CDE6-40C2-B9AB-DB396B3C440B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.127:*:*:*:*:*:*:*", "matchCriteriaId": "48944761-F3B4-448C-B665-F30C66F8B2C3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.128:*:*:*:*:*:*:*", "matchCriteriaId": "EB292BA1-7FF4-4C24-97F5-97C99DD8583F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.1.129:*:*:*:*:*:*:*", "matchCriteriaId": "9F502B60-1ED5-45E8-A3AF-9947912FCC45" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.5:*:*:*:*:*:*:*", "matchCriteriaId": "7E0FA8E2-3E8F-481E-8C39-FB00A9739DFC" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.5.50.10:*:*:*:*:*:*:*", "matchCriteriaId": "434B995D-BB1E-48FD-AB92-33E95EC75C1C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.5.51.10:*:*:*:*:*:*:*", "matchCriteriaId": "48B0E1CE-44E0-4A3E-85D1-F1391FDB3B5E" }, { "vulnerable": true, "criteria": "cpe:2.3:o:citrix:netscaler_gateway_firmware:10.5e:*:*:*:*:*:*:*", "matchCriteriaId": "4C6A8316-7943-4951-8FB7-A14D0FAB8F3E" } ] } ] } ], "references": [ { "url": "http://security-assessment.com/files/documents/advisory/Citrix-Netscaler-Final.pdf", "source": "cve@mitre.org" }, { "url": "http://support.citrix.com/article/CTX201149", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/75505", "source": "cve@mitre.org" }, { "url": "http://www.securitytracker.com/id/1032762", "source": "cve@mitre.org" }, { "url": "http://security-assessment.com/files/documents/advisory/Citrix-Netscaler-Final.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://support.citrix.com/article/CTX201149", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/bid/75505", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securitytracker.com/id/1032762", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }