Skip to content
COOEY

EXPOSURES › CVE-2017-6316

CVE-2017-6316

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-6316 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Citrix NetScaler and XenMobile Server management interfaces allowed unauthenticated remote attackers to execute arbitrary code as root.

An unauthenticated remote code execution flaw in Citrix NetScaler SD-WAN, CloudBridge, and XenMobile Server let attackers gain root access without authentication. DIB organizations must patch these products immediately to prevent lateral movement and data exfiltration. This is a known, actively exploited vulnerability that should have been mitigated through timely patching.

Shame score — A critical RCE flaw in widely deployed enterprise products was actively exploited in the wild, indicating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized