CVE-2018-5314: Citrix NetScaler Application Delivery Controller
High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Affected products
- Citrix NetScaler Application Delivery Controller: version 11.0 only; version 11.1 only; version 12.0 only
- Citrix NetScaler Gateway: version 11.0 only; version 11.1 only; version 12.0 only
- Citrix NetScaler SD-WAN: version 9.3.0 only
Published 2018-03-01. Last modified 2026-06-17.