cbcvebase.
CVE-2017-17382
published 2017-12-13

CVE-2017-17382: Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and…

PriorityP340medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
13.82%
96.0th percentile
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

Affected

9 ranges
VendorProductVersion rangeFixed in
citrixapplication_delivery_controller_firmware
citrixapplication_delivery_controller_firmware
citrixapplication_delivery_controller_firmware
citrixapplication_delivery_controller_firmware
citrixnetscaler_adc_gateway
citrixnetscaler_gateway_firmware
citrixnetscaler_gateway_firmware
citrixnetscaler_gateway_firmware
citrixnetscaler_gateway_firmware

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable products are Citrix NetScaler ADC and NetScaler Gateway; detect exploitation attempts by monitoring for Bleichenbacher RSA padding oracle (ROBOT attack) patterns in TLS handshake traffic — repeated RSA key exchange attempts with crafted PKCS#1 v1.5 padding
  • ·Vulnerable builds: NetScaler ADC/Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22. Ensure patched builds are deployed to remediate the ROBOT attack surface.

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.