CVE-2016-9028 — Citrix Netscaler Application Delivery Controller Firmware vulnerability
Severity
8.8HIGHNVD
EPSS
0.5%
top 35.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateMay 17
Description
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages9 packages
🔴Vulnerability Details
1GHSA▶
GHSA-mh5q-g25f-j24m: Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10↗2022-05-17