5.9

CVE-2015-3642

The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CitrixNetscaler Application Delivery Controller Version-
   CitrixNetscaler Firmware Version9.0
   CitrixNetscaler Firmware Version9.1
   CitrixNetscaler Firmware Version9.2
   CitrixNetscaler Firmware Version10.0
   CitrixNetscaler Firmware Version10.1
   CitrixNetscaler Firmware Version10.1e
   CitrixNetscaler Firmware Version10.5
   CitrixNetscaler Firmware Version10.5e
CitrixNetScaler Gateway Version-
   CitrixNetscaler Firmware Version9.0
   CitrixNetscaler Firmware Version9.1
   CitrixNetscaler Firmware Version9.2
   CitrixNetscaler Firmware Version10.0
   CitrixNetscaler Firmware Version10.1
   CitrixNetscaler Firmware Version10.1e
   CitrixNetscaler Firmware Version10.5
   CitrixNetscaler Firmware Version10.5e
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.494
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.