CVE-2014-2881
Citrix Netscaler Diffie-Hellman Key Exchange Issue
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.
Vulnerabilidad no especificada en la implementación de acuerdo clave Diffie-Hellman en el Applet Java de gestión de la interfaz gráfica de usuario en Citrix NetScaler Application Delivery Controller (ADC) y NetScaler Gateway anterior a 9.3-66.5 y 10.x anterior a 10.1-122.17 tiene impacto y vectores desconocidos.
The remote configuration Java applet in Citrix Netscaler versions prior to 10.1-122.17/9.3-66.5 contains a poor implementation of the Diffie-Hellman key exchange algorithm. The random number generator used to produce secret values is the java.util.Random class, which is not of cryptographic quality. Publicly known predictors exist for the underlying RNG, and the seed is either 32-bit or 48-bit depending on the host system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-04-17 CVE Reserved
- 2014-05-01 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1030180 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://support.citrix.com/article/CTX140651 | 2014-07-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Netscaler Access Gateway Firmware Search vendor "Citrix" for product "Netscaler Access Gateway Firmware" | 9.3 Search vendor "Citrix" for product "Netscaler Access Gateway Firmware" and version "9.3" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | - | - |
Affected
|
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Firmware Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" | 10.1 Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" and version "10.1" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | - | - |
Affected
|
Citrix Search vendor "Citrix" | Netscaler Access Gateway Firmware Search vendor "Citrix" for product "Netscaler Access Gateway Firmware" | <= 10.1.e Search vendor "Citrix" for product "Netscaler Access Gateway Firmware" and version " <= 10.1.e" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Access Gateway Search vendor "Citrix" for product "Netscaler Access Gateway" | - | enterprise |
Affected
|
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Firmware Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" | <= 9.3.e Search vendor "Citrix" for product "Netscaler Application Delivery Controller Firmware" and version " <= 9.3.e" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Access Gateway Search vendor "Citrix" for product "Netscaler Access Gateway" | - | enterprise |
Affected
|