CVE-2019-13608
KEV ransomwarelargeUnauthenticated XXE Information Disclosure in Citrix StoreFront Server
CISA: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
Citrix StoreFront Server, the web portal component that publishes applications and desktops to end users in on-premises Citrix Virtual Apps and Desktops deployments, improperly restricts XML external entity processing (CWE-611) when handling XML input. An unauthenticated attacker who can reach an affected StoreFront endpoint that accepts XML can submit crafted XML containing external entity definitions, causing the server's XML parser to fetch attacker-specified local or external resources. Successful exploitation may allow the attacker to retrieve potentially sensitive information, commonly by reading files accessible to the server process, and requires no valid credentials or user interaction. Any organization running Citrix StoreFront Server is potentially affected; the source data does not specify exact affected or fixed versions, so administrators should consult Citrix's advisory for CVE-2019-13608. The flaw is being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 30% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.
What to do: Apply the updated Citrix StoreFront release specified in Citrix's advisory for CVE-2019-13608, per CISA's required action. Limit direct internet reachability of StoreFront endpoints and review web logs for XXE probing (XML requests containing DOCTYPE/ENTITY declarations). Prioritize patching given known ransomware use, especially where StoreFront is internet-exposed or reachable from compromised edge devices such as gateways.
| Citrix StoreFront Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
- Affected
- Citrix StoreFront Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- citrix
- Products
- storefront server
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.