NetScaler Unencrypted Web Management Interface

medium Nessus Plugin ID 29224

Synopsis

The remote web management interface does not encrypt connections.

Description

The remote Citrix NetScaler web management interface does use TLS or SSL to encrypt connections.

Solution

Consider disabling this port completely and using only HTTPS.

Plugin Details

Severity: Medium

ID: 29224

File Name: netscaler_web_unencrypted.nasl

Version: 1.11

Type: remote

Family: Web Servers

Published: 12/6/2007

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:citrix:netscaler

Required KB Items: www/netscaler