CVE-2018-7218
9.8
CRITICAL · CVSS 3.0 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.16% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-05-17 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| citrix | application delivery controller firmware |
| citrix | netscaler gateway firmware |
References
→ the Explorer · watch your stack · NVD