First published: Mon Jun 13 2016(Updated: )
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XenServer | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5302 has a high severity level due to its potential for remote exploitation on the management network.
To fix CVE-2016-5302, apply Hotfix XS70E003 or later for Citrix XenServer 7.0.
CVE-2016-5302 affects Citrix XenServer versions prior to Hotfix XS70E003 deployed in environments upgraded from earlier releases.
The potential impacts of CVE-2016-5302 include unauthorized access to the host by exploiting Active Directory credentials.
Yes, CVE-2016-5302 can be exploited remotely by attackers on the management network.