// For flags

CVE-2014-2881

Citrix Netscaler Diffie-Hellman Key Exchange Issue

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.

Vulnerabilidad no especificada en la implementación de acuerdo clave Diffie-Hellman en el Applet Java de gestión de la interfaz gráfica de usuario en Citrix NetScaler Application Delivery Controller (ADC) y NetScaler Gateway anterior a 9.3-66.5 y 10.x anterior a 10.1-122.17 tiene impacto y vectores desconocidos.

The remote configuration Java applet in Citrix Netscaler versions prior to 10.1-122.17/9.3-66.5 contains a poor implementation of the Diffie-Hellman key exchange algorithm. The random number generator used to produce secret values is the java.util.Random class, which is not of cryptographic quality. Publicly known predictors exist for the underlying RNG, and the seed is either 32-bit or 48-bit depending on the host system.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-04-17 CVE Reserved
  • 2014-05-01 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Citrix
Search vendor "Citrix"
Netscaler Access Gateway Firmware
Search vendor "Citrix" for product "Netscaler Access Gateway Firmware"
9.3
Search vendor "Citrix" for product "Netscaler Access Gateway Firmware" and version "9.3"
-
Affected
in Citrix
Search vendor "Citrix"
Netscaler Application Delivery Controller
Search vendor "Citrix" for product "Netscaler Application Delivery Controller"
--
Affected
Citrix
Search vendor "Citrix"
Netscaler Application Delivery Controller Firmware
Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware"
10.1
Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" and version "10.1"
-
Affected
in Citrix
Search vendor "Citrix"
Netscaler Application Delivery Controller
Search vendor "Citrix" for product "Netscaler Application Delivery Controller"
--
Affected
Citrix
Search vendor "Citrix"
Netscaler Access Gateway Firmware
Search vendor "Citrix" for product "Netscaler Access Gateway Firmware"
<= 10.1.e
Search vendor "Citrix" for product "Netscaler Access Gateway Firmware" and version " <= 10.1.e"
-
Affected
in Citrix
Search vendor "Citrix"
Netscaler Access Gateway
Search vendor "Citrix" for product "Netscaler Access Gateway"
-enterprise
Affected
Citrix
Search vendor "Citrix"
Netscaler Application Delivery Controller Firmware
Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware"
<= 9.3.e
Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" and version " <= 9.3.e"
-
Affected
in Citrix
Search vendor "Citrix"
Netscaler Access Gateway
Search vendor "Citrix" for product "Netscaler Access Gateway"
-enterprise
Affected