EXPOSURES › CVE-2019-13608
CVE-2019-13608
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCitrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.
An unauthenticated attacker could exploit a StoreFront Server XXE vulnerability to retrieve sensitive information, potentially leading to data breaches and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2). DIB organizations using StoreFront must immediately patch and review access controls.
Shame score — The vulnerability's exploitation by ransomware and lack of authentication requirement highlight a significant negligence in secure coding practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |