← Vulnerability feed

Vulnerability record · CVE-2018-5314 · published 1 March 2018

CVE-2018-5314: Citrix netscaler application delivery controller improper authentication vulnerability

Citrix · Netscaler Application Delivery Controller

Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.

7.5 CVSS 3.0 High EPSS 2.8% · top 13.7% CWE-287 · Improper authentication
7.5CVSS 3.0 base score, v2 5.0
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/103186 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040439 Third Party AdvisoryVDB Entry
https://support.citrix.com/article/CTX232199 Vendor Advisory
http://www.securityfocus.com/bid/103186 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040439 Third Party AdvisoryVDB Entry
https://support.citrix.com/article/CTX232199 Vendor Advisory

Track CVE-2018-5314 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.8CVE-2019-12989Citrix SD-WAN and NetScaler SD-WAN SQL injectionCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 are vulnerable to SQL injection. The flaw is remotely reachable without …KEVEPSS 95%analysed9.8CVE-2017-6316Citrix NetScaler SD-WAN cookie flaw allows root command executionCitrix NetScaler SD-WAN devices through v9.1.2.26.561201 accept a crafted CGISESSID cookie (CAKEPHP on older CloudBridge devices) that lets a remote …KEVEPSS 73%analysed9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEVEPSS 1.1%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEVEPSS 1.3%9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 23%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2018-5314), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.