ADC

签名更新版本 44

针对2020-04-27周发现的漏洞,将生成新的签名规则。您可以下载并配置这些签名规则,以保护您的设备免受安全漏洞攻击。

签名版本

签名与以下软件版本的 Citrix Application Delivery Controller (ADC) (ADC) 11.1、12.0、12.1、13.0 和 13.1 兼容。

NetScaler 版本 12.0 已达到生命周期终止 (EOL)。有关更多信息,请参阅 发布生命周期 页面。

注意:

启用发布主体和响应主体签名规则可能会影响 NetScaler CPU。

常见漏洞条目 (CVE) 见解

以下是签名规则、CVE ID 及其描述的列表。

签名规则 CVE ID 说明
999683 CVE-2020-9043 WEB-WORDPRESS wpCentral plug-in Prior To 1.5.1 - Connection Key Disclosure Vulnerability (CVE-2020-9043)
999684   WEB-WORDPRESS Duplicate-Post plug-in Version 3.2.3 and Prior - Persistent Cross-site Scripting
999685   WEB-WORDPRESS Duplicate-Post plug-in Version 3.2.3 and Prior - Persistent Cross-site Scripting
999686 CVE-2020-0618 WEB-MISC Microsoft SQL Server Reporting Services - Remote Code Execution Vulnerability (CVE-2020-0618)
999687 CVE-2019-16278 WEB-MISC Nostromo Nhttpd Prior to 1.3.7 - Strcutl Function Allows Unauthenticated Remote Code Execution (CVE-2019-16278)
999688 CVE-2019-1937 WEB-MISC Cisco UCS Director 6.6.0.0 to 6.6.1.0 and 6.7.0.0 to 6.7.1.0 - Authentication Bypass Vulnerability (CVE-2019-1937)
999689   WEB-WORDPRESS Duplicate-Post plug-in Version 3.2.3 and Prior - Persistent Cross-site Scripting
999690 CVE-2020-9006 WEB-WORDPRESS Popup Builder plug-in Prior to 3.0 - SQL Injection Via PHP Deserialization Vulnerability (CVE-2020-9006)
999691   WEB-WORDPRESS Duplicate-Post plug-in Version 3.2.3 and Prior - Persistent Cross-site Scripting
999692   WEB-MISC prevent request smuggling via content-length and transfer-encoding header
999693   WEB-WORDPRESS ThemeGrill Demo Importer plug-in Prior To 1.6.3 - Authentication Bypass And Database Wipe Vulnerability
999694 CVE-2019-17237 WEB-WORDPRESS IgniteUp Coming Soon and Maintenance Mode plug-in Prior to 3.4.1 - CSRF Vulnerability Via Message (CVE-2019-17237)
999695 CVE-2019-17237 WEB-WORDPRESS IgniteUp Coming Soon and Maintenance Mode plug-in Prior to 3.4.1 - CSRF Vulnerability Via Subject (CVE-2019-17237)
签名更新版本 44