Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3642


The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).


Published

2017-08-02T19:29:00.477

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System citrix netscaler_firmware 9.0 No
Operating System citrix netscaler_firmware 9.1 No
Operating System citrix netscaler_firmware 9.2 No
Operating System citrix netscaler_firmware 10.0 No
Operating System citrix netscaler_firmware 10.1 No
Operating System citrix netscaler_firmware 10.1e No
Operating System citrix netscaler_firmware 10.5 No
Operating System citrix netscaler_firmware 10.5e No
Hardware citrix netscaler_application_delivery_controller - Yes
Operating System citrix netscaler_firmware 9.0 No
Operating System citrix netscaler_firmware 9.1 No
Operating System citrix netscaler_firmware 9.2 No
Operating System citrix netscaler_firmware 10.0 No
Operating System citrix netscaler_firmware 10.1 No
Operating System citrix netscaler_firmware 10.1e No
Operating System citrix netscaler_firmware 10.5 No
Operating System citrix netscaler_firmware 10.5e No
Hardware citrix netscaler_gateway - Yes

References