Identify and remediate vulnerabilities for CVE-2021-22956
<number of> NetScaler instances are impacted by common vulnerabilities and exposures (CVEs), you can see all the instances vulnerable due to this specific CVE. To check the details of the CVE-2021-22956 impacted instances, select CVE-2021-22956 and click View Affected Instances.
<number of> NetScaler instances impacted by CVEs window appear. Here you see the count and details of the NetScaler instances impacted by CVE-2021-22956.
Identify CVE-2021-22956 impacted instances
httpd.conf file) and maximum client connections (maxclient) parameters to determine if an instance is vulnerable or not. The information the script shares with NetScaler Console service is the vulnerability status in Boolean (true or false). The script also gives back to NetScaler Console service a list of counts for max_clients for different network interfaces, for example local host, NSIP, and SNIP with management access.
Remediate CVE-2021-22956
-
Upgrading the vulnerable NetScaler instances to a release and build that has the fix.
-
Applying the required configuration commands using the customizable built-in configuration template in configuration jobs.
Step 1: Upgrade the vulnerable NetScaler instances
Step 2: Apply configuration commands
<number of> NetScaler instances impacted by CVEs window, select the instance impacted by CVE-2021-2295 and click Proceed to configuration job workflow. The workflow includes the following steps.
-
Customizing the configuration.
-
Reviewing the auto-populated impacted instances.
-
Specifying inputs for variables for the job.
-
Reviewing the final config with variable inputs populated.
-
Running the job.
-
For a NetScaler instance impacted by multiple CVEs (such as CVE-2020-8300, CVE-2021-22927, CVE-2021-22920, and CVE-2021-22956): when you select the instance and click Proceed to configuration job workflow, the built-in configuration template does not auto-populate under Select configuration. Drag and drop the appropriate config job template under Security Advisory Template manually to the config job pane on the right side.
-
For multiple NetScaler instances that are impacted by CVE-2021-22956 only: you can run config jobs on all instances at once. For example, you've NetScaler 1, NetScaler 2, and NetScaler 3, and all of them are impacted only by CVE-2021-22956. Select all these instances and click Proceed to configuration job workflow, and the built-in configuration template auto-populates under Select configuration.
-
For multiple NetScaler instances impacted by CVE-2021-22956 and one or more other CVEs (such as CVE-2020-8300, CVE-2021-22927, and CVE-2021-22920), which require remediation to be applied to each NetScaler at a time: when you select these instances and click Proceed to configuration job workflow, an error message appears telling you to run the config job on each NetScaler at a time.
Step 1: Select configuration
Step 2: Select the instance
rc.netscaler is synced across all HA and cluster nodes, making the remediation persistent after each restart.
Step 3: Specify variable values
max_client.
max_client and then upload the file to the NetScaler Console server.
max_client value is 30. You can set the value according to your present value. However, it should not be zero, and it should be less than or equal to the max_client set in the /etc/httpd.conf file. You can check the present value set in the Apache HTTP Server configuration file /etc/httpd.conf by searching the string MaxClients, in the NetScaler instance
Step 4: Preview the configuration
Step 5: Run the job