ZeroHour

CVE-2017-6316

KEV PoC moderate

Unauthenticated Root RCE in Citrix NetScaler SD-WAN / CloudBridge via Session Cookie

CISA: Citrix Multiple Products Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2017-6316 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in the web management interface of Citrix NetScaler SD-WAN appliances: the session cookie value is not properly sanitized before being used in a system shell, so a crafted CGISESSID cookie (CAKEPHP on CloudBridge-branded devices) in a plain HTTP request to the management interface causes attacker-supplied shell commands to run as root. No credentials or user interaction are required, only network reachability to the appliance's management web interface, and successful exploitation gives an attacker full root control of the device, including configuration theft, pivoting into the connected branch network, and persistence. CISA lists Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN (the former product name), and XenMobile Server as affected. Devices running builds through 9.1.2.26.561201 are vulnerable. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) and has a public PoC/Metasploit module (Exploit-DB 42345); with EPSS at 72.6% (99th percentile), near-term exploitation is considered very likely.

What to do: Upgrade Citrix NetScaler SD-WAN / CloudBridge Virtual WAN appliances to a build newer than 9.1.2.26.561201 per Citrix's security advisory (the CISA KEV required action is to apply updates per vendor instructions), and apply vendor updates for XenMobile Server if deployed. Until patched, restrict the appliance's web management interface to trusted management networks or a VPN rather than the public internet, and review device web-server access logs for anomalous CGISESSID/CAKEPHP cookie values indicating exploitation attempts. Given the 72.6% EPSS and KEV listing, prioritize any internet-facing appliances first.

Affected
Citrix NetScaler SD-WAN (Enterprise)through 9.1.2.26.561201
Citrix CloudBridge Virtual WAN (former name of NetScaler SD-WAN; affected via the CAKEPHP session cookie)same product line, through 9.1.2.26.561201
Citrix XenMobile Server
Estimated exposure
moderate≈10k–100k deployed Citrix SD-WAN/CloudBridge branch appliances, of which likely only a few thousand expose the management interface to the internet — No public install-base figure is available for this product line, so the estimate is based on deployment patterns: Citrix SD-WAN/CloudBridge was a niche branch-office appliance line in the enterprise WAN-optimization/SD-WAN market, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

CISA Known Exploited Vulnerability
Affected
Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
netscaler sd-wan
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.