First published: Thu Jul 20 2017(Updated: )
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler SD-WAN | <=9.1.2.26.561201 | |
Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | ||
<=9.1.2.26.561201 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.