CVE-2017-6316
Last modified
CVE-2017-6316 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.. CISA has confirmed active exploitation in the wild. EPSS estimates a 72.60% chance of exploitation in the next 30 days.
Description
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Netscaler Sd-Wan | <= 9.1.2.26.561201 |
References
- https://www.securityfocus.com/bid/99943Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id/1039019Broken Link, Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX225990Permissions Required
- https://www.exploit-db.com/exploits/42345/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42346/Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/99943Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id/1039019Broken Link, Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX225990Permissions Required
- https://www.exploit-db.com/exploits/42345/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42346/Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6316US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2017-6316?
How severe is CVE-2017-6316?
How do I fix CVE-2017-6316?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-6310An issue was discovered in tnef before 1.4.13. Four type con…
- CVE-2017-6311gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-depend…7.5
- CVE-2017-6312Integer overflow in io-ico.c in gdk-pixbuf allows context-de…5.5
- CVE-2017-6313Integer underflow in the load_resources function in io-icns.…7.1
- CVE-2017-6314The make_available_at_least function in io-tiff.c in gdk-pix…5.5
- CVE-2017-6315Astaro Security Gateway (aka ASG) 7 allows remote attackers …
- CVE-2017-6317Memory leak in the add_shader_program function in vrend_rend…
- CVE-2017-6318saned in sane-backends 1.0.25 allows remote attackers to obt…
- CVE-2017-6319The dex_parse_debug_item function in libr/bin/p/bin_dex.c in…
- CVE-2017-6320A remote command injection vulnerability exists in the Barra…8.8
- CVE-2017-6323The Symantec Management Console prior to ITMS 8.1 RU1, ITMS …
- CVE-2017-6324The Symantec Messaging Gateway, when processing a specific e…
Are you affected by CVE-2017-6316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
