What evidence is enough to treat a NetScaler appliance as patched?
A user asks whether a fixed-build receipt or a compromise assessment that still matches the appliance meets the bar, pointing to a KEV catalog addition and CISA’s forensic-triage note.
TLDR
A user calls the KEV catalog addition the “public clock” and CISA’s forensic-triage note the “private one.” They ask what would justify treating a NetScaler appliance as patched: a fixed-build receipt, or a compromise assessment that still matches the appliance.
Combined views
26
1 Source, first seen 8h ago