CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
AI Score
Confidence
High
EPSS
Percentile
87.7%
Improper Control of Generation of Code (‘Code Injection’) in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
[
{
"defaultStatus": "unaffected",
"product": "NetScaler ADC ",
"vendor": "Cloud Software Group",
"versions": [
{
"lessThan": "12.35",
"status": "affected",
"version": "14.1",
"versionType": "patch"
},
{
"lessThan": "51.15",
"status": "affected",
"version": "13.1",
"versionType": "patch"
},
{
"lessThan": "92.21",
"status": "affected",
"version": "13.0 ",
"versionType": "patch"
},
{
"lessThan": "37.176",
"status": "affected",
"version": " 13.1-FIPS",
"versionType": "patch"
},
{
"lessThan": "55.302",
"status": "affected",
"version": "12.1-FIPS",
"versionType": "patch"
},
{
"lessThan": "55.302",
"status": "affected",
"version": "12.1-NDcPP",
"versionType": "patch"
}
]
},
{
"defaultStatus": "unaffected",
"product": "NetScaler Gateway",
"vendor": "Cloud Software Group",
"versions": [
{
"lessThan": "12.35",
"status": "affected",
"version": "14.1",
"versionType": "patch"
},
{
"lessThan": "51.15",
"status": "affected",
"version": "13.1",
"versionType": "patch"
},
{
"lessThan": "92.21",
"status": "affected",
"version": "13.0",
"versionType": "patch"
}
]
}
]
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
AI Score
Confidence
High
EPSS
Percentile
87.7%