Executive brief
A remote code execution vulnerability exists in the management interface of Citrix NetScaler SD-WAN and CloudBridge devices. An unauthenticated attacker can execute arbitrary shell commands as root by manipulating the CGISESSID or CAKEPHP cookies.
Affected products
- Citrix NetScaler SD-WAN Enterprise Edition through 9.1.2.26.561201
- Citrix NetScaler SD-WAN Standard Edition through 9.1.2.26.561201
- Citrix CloudBridge Virtual WAN Edition through 9.1.2.26.561201
- Citrix XenMobile Server
Timeline
- 2017-07-20: disclosed: NVD Published Date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Reported as exploited in the wild in advisory metadata