CVE-2018-18571: Critical severity citrix xenmobile vulnerability
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Citrix XenMobile Server vulnerability?
The vulnerability ID for this Citrix XenMobile Server vulnerability is CVE-2018-18571.
What is the severity rating for this vulnerability?
The severity rating for this vulnerability is 9.1 (Critical).
What is the affected software?
The affected software is Citrix XenMobile Server versions 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3.
How can an attacker exploit this vulnerability?
An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108081) and [Citrix Support](https://support.citrix.com/article/CTX247736).