CVE-2017-17382 describes a Bleichenbacher RSA padding oracle vulnerability, also known as a ROBOT attack, affecting specific versions of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. This medium-severity vulnerability (CVSS 5.9) allows remote attackers to decrypt TLS ciphertext data due to a weakness in cryptographic practices (CWE-327), with a high impact on confidentiality. While not in the KEV catalog, its EPSS score indicates a higher than average likelihood of exploitation, and a Metasploit scanner module exists. The vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:10.5:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:11.0:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:11.1:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:12.0:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:o:citrix:netscaler_gateway_firmware:10.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.