ZeroHour

CVE-2019-13608

KEV ransomwarelarge

Unauthenticated XXE Information Disclosure in Citrix StoreFront Server

CISA: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

CVSS 3.1
7.5 high
EPSS
30%p98
Published
()
KEV added
AI analysis

Citrix StoreFront Server, the web portal component that publishes applications and desktops to end users in on-premises Citrix Virtual Apps and Desktops deployments, improperly restricts XML external entity processing (CWE-611) when handling XML input. An unauthenticated attacker who can reach an affected StoreFront endpoint that accepts XML can submit crafted XML containing external entity definitions, causing the server's XML parser to fetch attacker-specified local or external resources. Successful exploitation may allow the attacker to retrieve potentially sensitive information, commonly by reading files accessible to the server process, and requires no valid credentials or user interaction. Any organization running Citrix StoreFront Server is potentially affected; the source data does not specify exact affected or fixed versions, so administrators should consult Citrix's advisory for CVE-2019-13608. The flaw is being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 30% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

What to do: Apply the updated Citrix StoreFront release specified in Citrix's advisory for CVE-2019-13608, per CISA's required action. Limit direct internet reachability of StoreFront endpoints and review web logs for XXE probing (XML requests containing DOCTYPE/ENTITY declarations). Prioritize patching given known ransomware use, especially where StoreFront is internet-exposed or reachable from compromised edge devices such as gateways.

Affected
Citrix StoreFront Server
Estimated exposure
largetens of thousands of Citrix StoreFront server deployments (order-of-magnitude estimate; exact counts unknown) — Estimated from deployment patterns - StoreFront is the standard access portal for on-premises Citrix Virtual Apps and Desktops and is typically deployed as enterprise server groups - together with public internet scans that have shown on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CISA Known Exploited Vulnerability
Affected
Citrix StoreFront Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
citrix
Products
storefront server
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.