Skip to content
COOEY

EXPOSURES › CVE-2019-13608

CVE-2019-13608

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-13608 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatcheddata-breach

Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.

An unauthenticated attacker could exploit a StoreFront Server XXE vulnerability to retrieve sensitive information, potentially leading to data breaches and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2). DIB organizations using StoreFront must immediately patch and review access controls.

Shame score — The vulnerability's exploitation by ransomware and lack of authentication requirement highlight a significant negligence in secure coding practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized