CVE-2017-6316
KEV PoC moderateUnauthenticated Root RCE in Citrix NetScaler SD-WAN / CloudBridge via Session Cookie
CISA: Citrix Multiple Products Remote Code Execution Vulnerability
CVE-2017-6316 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in the web management interface of Citrix NetScaler SD-WAN appliances: the session cookie value is not properly sanitized before being used in a system shell, so a crafted CGISESSID cookie (CAKEPHP on CloudBridge-branded devices) in a plain HTTP request to the management interface causes attacker-supplied shell commands to run as root. No credentials or user interaction are required, only network reachability to the appliance's management web interface, and successful exploitation gives an attacker full root control of the device, including configuration theft, pivoting into the connected branch network, and persistence. CISA lists Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN (the former product name), and XenMobile Server as affected. Devices running builds through 9.1.2.26.561201 are vulnerable. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) and has a public PoC/Metasploit module (Exploit-DB 42345); with EPSS at 72.6% (99th percentile), near-term exploitation is considered very likely.
What to do: Upgrade Citrix NetScaler SD-WAN / CloudBridge Virtual WAN appliances to a build newer than 9.1.2.26.561201 per Citrix's security advisory (the CISA KEV required action is to apply updates per vendor instructions), and apply vendor updates for XenMobile Server if deployed. Until patched, restrict the appliance's web management interface to trusted management networks or a VPN rather than the public internet, and review device web-server access logs for anomalous CGISESSID/CAKEPHP cookie values indicating exploitation attempts. Given the 72.6% EPSS and KEV listing, prioritize any internet-facing appliances first.
| Citrix NetScaler SD-WAN (Enterprise) | through 9.1.2.26.561201 |
| Citrix CloudBridge Virtual WAN (former name of NetScaler SD-WAN; affected via the CAKEPHP session cookie) | same product line, through 9.1.2.26.561201 |
| Citrix XenMobile Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
- Affected
- Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- netscaler sd-wan
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.