what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Citrix Netscaler 10.0 Denial Of Service

Citrix Netscaler 10.0 Denial Of Service
Posted Oct 3, 2013
Authored by S. Viehbock | Site sec-consult.com

A vulnerability was found in the nsconfigd daemon (TCP port 3008/SSL and 3010). This daemon can be crashed by sending a specially crafted message. No prior authentication is necessary. A watchdog daemon (pitboss) automatically restarts nsconfigd after the first six crashes and then reboots the appliance. By sending just a few packets the appliance can be kept in a constant reboot loop resulting in total loss of availability. The vulnerabilities have been verified to exist in Citrix NetScaler VPX (Build 70.7.nc), which was the most recent version at the time of discovery.

tags | advisory, tcp, vulnerability
SHA-256 | 58dcdce47632f720bc628f80305effb40ef074b20b017ef9442a1abcc451ee3b

Citrix Netscaler 10.0 Denial Of Service

Change Mirror Download
SEC Consult Vulnerability Lab Security Advisory < 20131003-0 >
=======================================================================
title: nsconfigd NSRPC_REMOTECMD Denial of service vulnerability
product: Citrix NetScaler
vulnerable version: NetScaler 10.0 (Build <76.7)
fixed version: NetScaler 10.0 (Build >=76.7)
not affected: NetScaler 10.1 and 9.3
impact: Critical
homepage: http://www.citrix.com
found: 2012-12-10
by: Stefan Viehböck
SEC Consult Vulnerability Lab
https://www.sec-consult.com
=======================================================================

Vendor/product description:
---------------------------
"Citrix NetScaler helps organizations build enterprise cloud networks that
embody the characteristics and capabilities that define public cloud services,
such as elasticity, expandability and simplicity. NetScaler brings to
enterprise IT leaders multiple advanced technologies that were previously
available only to large public cloud providers."

"As an undisputed leader of service and application delivery, Citrix NetScaler
solutions are deployed in thousands of networks around the globe to optimize,
secure and control the delivery of all enterprise and cloud services. They
deliver 100 percent application availability, application and database server
offload, acceleration and advanced attack protection. Deployed directly in
front of web and database servers, NetScaler solutions combine high-speed load
balancing and content switching, http compression, content caching, SSL
acceleration, application flow visibility and a powerful application firewall
into a single, easy-to-use platform."

URL: http://www.citrix.com/products/netscaler-application-delivery-controller/overview.html


Vulnerability overview/description:
-----------------------------------
A vulnerability was found in the nsconfigd daemon (TCP port 3008 (SSL) and
3010). This daemon can be crashed by sending a specially crafted message.
No prior authentication is necessary. A watchdog daemon (pitboss) automatically
restarts nsconfigd after the first six crashes and then reboots the appliance.
By sending just a few packets the appliance can be kept in a constant reboot
loop resulting in total loss of availability.


Proof of concept:
-----------------
The nsconfigd daemon can be crashed for six times using the following Python
script. Subsequently the appliance reboots.

Detailed proof of concept exploits have been removed for this vulnerability.


Vulnerable / tested versions:
-----------------------------
The vulnerabilities have been verified to exist in Citrix NetScaler VPX (Build
70.7.nc), which was the most recent version at the time of discovery.


Vendor contact timeline:
------------------------
2013-03-27: Contacting vendor through secure@citrix.com.
2013-03-28: Vendor provides encryption key.
2013-03-28: Sending advisory via secure channel.
2013-03-28: Vendor confirms receipt of advisory.
2013-04-08: Requesting status update.
2013-04-19: Requesting status update (again).
2013-04-22: Vendor confirms issues, is "in the process of scheduling required
changes".
2013-06-05: Requesting status update.
2013-06-25: Requesting status update (again).
2013-06-25: Vendor is still "in the process of scheduling changes".
2013-08-14: Requesting status update (again) and setting deadline (Oct. 3rd).
2013-09-18: Vendor provides release dates for the update (Oct. 1st and 2nd).
2013-10-03: SEC Consult releases coordinated security advisory.


Solution:
---------
Update to Citrix NetScaler 10.0 Build 76.7.

Vendor information can be found at:
http://support.citrix.com/article/ctx139017


Workaround:
-----------
No workaround available.


Advisory URL:
-------------
https://www.sec-consult.com/en/Vulnerability-Lab/Advisories.htm


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SEC Consult Vulnerability Lab

SEC Consult
Vienna - Bangkok - Frankfurt/Main - Montreal - Singapore - Vilnius

Headquarter:
Mooslackengasse 17, 1190 Vienna, Austria
Phone: +43 1 8903043 0
Fax: +43 1 8903043 15

Mail: research at sec-consult dot com
Web: https://www.sec-consult.com
Blog: http://blog.sec-consult.com
Twitter: https://twitter.com/sec_consult

EOF Stefan Viehböck / @2013
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close