Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 및 10.5-70.18 이전 버전의 Citrix ADC와 Citrix Gateway, 그리고 11.1.1a, 11.0.3d 및 10.2.7 이전 버전의 Citrix SDWAN WAN-OP에 부적절한 입력 검증이 존재하여 권한이 낮은 사용자에게 제한적인 정보가 노출됩니다.
13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 및 10.5-70.18 이전 버전의 Citrix ADC와 Citrix Gateway, 그리고 11.1.1a, 11.0.3d 및 10.2.7 이전 버전의 Citrix SDWAN WAN-OP에 부적절한 입력 검증이 존재하여 권한이 낮은 사용자에게 제한적인 정보가 노출됩니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
영향 제품·버전
제품 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
영향 버전 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7, >= 10.5 < 10.5-70.18, >= 11.1 < 11.1-64.14, >= 12.0 < 12.0-63.21, >= 12.1 < 12.1-57.18, >= 13.0 < 13.0-58.30, >= 10.2 < 10.2.7, >= 11.0 < 11.0.3d, >= 11.1 < 11.1.1a, < 1.0.0.137
수정 버전 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance 10.5-70.18, 11.1-64.14, 12.0-63.21, 12.1-57.18, 13.0-58.30, 10.2.7, 11.0.3d, 11.1.1a, 1.0.0.137
Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance의 현재 전체 버전이 공식 영향 범위(Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7, >= 10.5 < 10.5-70.18, >= 11.1 < 11.1-64.14, >= 12.0 < 12.0-63.21, >= 12.1 < 12.1-57.18, >= 13.0 < 13.0-58.30, >= 10.2 < 10.2.7, >= 11.0 < 11.0.3d, >= 11.1 < 11.1.1a, < 1.0.0.137)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply updates per vendor instructions.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance 10.5-70.18, 11.1-64.14, 12.0-63.21, 12.1-57.18, 13.0-58.30, 10.2.7, 11.0.3d, 11.1.1a, 1.0.0.137 기준을 충족하는지 확인합니다. 이어서 경로 조작·임의 파일 접근 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.