Impact
The vulnerability permits an attacker who can send requests to a NetScaler ADC or Gateway device to read any file on the system when management access to the NSIP, Cluster Management IP, or SNIP is enabled. This allows exposure of sensitive configuration files, credentials, or other confidential data. The weakness is a path traversal type flaw that permits disallowed path access (CWE‑73).
Affected Systems
All NetScaler ADC and NetScaler Gateway devices that enable management access to the NSIP, Cluster Management IP, or SNIP are potentially affected. No specific version numbers are provided in the CVE data, so any revision allowing such access should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available, so the exploitation likelihood remains uncertain. The CVE is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation to date. The likely attack vector is an external network connection to the device’s management interfaces; no user credentials are required.
OpenCVE Enrichment