Описание
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.1-37.272 (исключая)Версия до 13.1-37.272 (исключая)Версия от 13.1 (включая) до 13.1-63.18 (исключая)Версия от 14.1 (включая) до 14.1-72.61 (исключая)Версия от 13.1 (включая) до 13.1-63.18 (исключая)Версия от 14.1 (включая) до 14.1-72.61 (исключая)
Одно из
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-66.68:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00472
Низкий
7.5 High
CVSS3
Дефекты
CWE-401
Связанные уязвимости
CVSS3: 7.5
github
около 1 месяца назад
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
EPSS
Процентиль: 38%
0.00472
Низкий
7.5 High
CVSS3
Дефекты
CWE-401