EXPOSURES › CVE-2017-6316
CVE-2017-6316
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix NetScaler and XenMobile Server management interfaces allowed unauthenticated remote attackers to execute arbitrary code as root.
An unauthenticated remote code execution flaw in Citrix NetScaler SD-WAN, CloudBridge, and XenMobile Server let attackers gain root access without authentication. DIB organizations must patch these products immediately to prevent lateral movement and data exfiltration. This is a known, actively exploited vulnerability that should have been mitigated through timely patching.
Shame score — A critical RCE flaw in widely deployed enterprise products was actively exploited in the wild, indicating severe negligence in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |