cvedb.io
CVE-2019-6485
MEDIUM · CVSS 5.9
EPSS exploitation probability: 0%
Published 2019-02-22T23:29:00.283 · Last modified 2026-06-17T02:39:07.300

Summary

Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.

Affected products

citrix — netscaler_gateway_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when citrix ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.