CVE-2015-5080: Citrix NetScaler Application Delivery Controller Firmware
High severity, CVSS 9.0. EPSS: 4% chance of exploitation in the next 30 days.
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to rapi/ipsec_logs.
Affected products
- Citrix NetScaler Application Delivery Controller Firmware: version 10.1 only; version 10.1.120.1316.e only; version 10.1.121 only; version 10.1.122 only; version 10.1.123 only; version 10.1.124 only; …
- Citrix NetScaler Gateway Firmware: version 10.1.120.1316.e only; version 10.1.121 only; version 10.1.122 only; version 10.1.123 only; version 10.1.124 only; version 10.1.125 only; …
Published 2015-07-16. Last modified 2026-06-17.