CVE-2017-17382
published 2017-12-13CVE-2017-17382: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and…
PriorityP340medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
13.82%
96.0th percentile
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | application_delivery_controller_firmware | — | — |
| citrix | application_delivery_controller_firmware | — | — |
| citrix | application_delivery_controller_firmware | — | — |
| citrix | application_delivery_controller_firmware | — | — |
| citrix | netscaler_adc_gateway | — | — |
| citrix | netscaler_gateway_firmware | — | — |
| citrix | netscaler_gateway_firmware | — | — |
| citrix | netscaler_gateway_firmware | — | — |
| citrix | netscaler_gateway_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable products are Citrix NetScaler ADC and NetScaler Gateway; detect exploitation attempts by monitoring for Bleichenbacher RSA padding oracle (ROBOT attack) patterns in TLS handshake traffic — repeated RSA key exchange attempts with crafted PKCS#1 v1.5 padding ↗
- ·Vulnerable builds: NetScaler ADC/Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22. Ensure patched builds are deployed to remediate the ROBOT attack surface. ↗
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwq4-vph9-wfm2: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10
ghsa_unreviewed·2022-05-13
CVE-2017-17382 [MEDIUM] CWE-327 GHSA-fwq4-vph9-wfm2: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Citrix
CVE-2017-17382: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19
vendor_citrix·2017-12-13·CVSS 5.9
CVE-2017-17382 [MEDIUM] CWE-327 CVE-2017-17382: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19
CVE-2017-17382: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102173http://www.securitytracker.com/id/1039985https://robotattack.org/https://support.citrix.com/article/ctx230238https://www.kb.cert.org/vuls/id/144389http://www.securityfocus.com/bid/102173http://www.securitytracker.com/id/1039985https://robotattack.org/https://support.citrix.com/article/ctx230238https://www.kb.cert.org/vuls/id/144389
2017-12-13
Published