5
CVE-2015-7996
- EPSS 0.29%
- Veröffentlicht 17.11.2015 15:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Netscaler Application Delivery Controller Firmware Version10.1
Citrix ≫ Netscaler Application Delivery Controller Firmware Version10.5
Citrix ≫ Netscaler Service Delivery Appliance Service Vm Version10.5e
Citrix ≫ Netscaler Gateway Firmware Version10.1
Citrix ≫ Netscaler Gateway Firmware Version10.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.29% | 0.497 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.