CVE-2017-5933: Citrix NetScaler Application Delivery Controller Firmware
Medium severity, CVSS 5.9. EPSS: 3.2% chance of exploitation in the next 30 days.
Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.
Affected products
- Citrix NetScaler Application Delivery Controller Firmware: up to and including 10.5.65.11; up to and including 11.0.69.12; up to and including 11.1.51.21
Published 2017-02-08. Last modified 2026-06-17.