CVE-2017-6316criticalunder attack

CVE-2017-6316

Published · Updated

100Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 73%
from disclosure to weapon0 days
Published on NVDJul 20
1st PoCJul 19
CISA KEV+1709d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

Citrix NetScaler SD-WAN devices contain a critical flaw where attackers can execute commands with root privileges by manipulating a cookie in web requests. This allows complete takeover of the device without authentication.

Technical detail

Remote unauthenticated attackers can execute arbitrary shell commands as root by crafting requests with a malicious CGISESSID cookie (or CAKEPHP on CloudBridge devices). The vulnerability exists in versions through v9.1.2.26.561201 and requires no authentication or user interaction; the attack vector is network-based HTTP requests to the device's web interface.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.