CVE-2017-6316: Citrix Multiple Products Remote Code Execution Vulnerability
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
Other sources
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6316?
CVE-2017-6316 is considered a critical vulnerability due to its potential for remote code execution as root.
How do I fix CVE-2017-6316?
To fix CVE-2017-6316, upgrade Citrix NetScaler SD-WAN devices to version 9.1.2.27 or later.
What devices are affected by CVE-2017-6316?
CVE-2017-6316 affects Citrix NetScaler SD-WAN devices running up to version 9.1.2.26.561201.
What attack vectors are associated with CVE-2017-6316?
CVE-2017-6316 allows remote attackers to execute arbitrary shell commands via a crafted CGISESSID cookie.
What impact does CVE-2017-6316 have on system security?
CVE-2017-6316 can lead to unauthorized access and complete control over affected devices by an attacker.