PT-2018-14320 · Citrix · Xen Mobile

Glyn Wintle

·

Publicado

2018-10-24

·

Atualizado

2024-08-05

·

CVE-2018-18013

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen Mobile versions prior to 10.8.0
Description The issue arises from a service listening on port 5001 within the firewall of Xen Mobile, which accepts unauthenticated input. This service deserializes raw serialized Java objects into Java objects in memory, potentially leading to remote code execution. The vendor disputes this as a vulnerability, citing mitigation by an internal firewall limiting access to configuration services to localhost.
Recommendations For versions prior to 10.8.0, as a temporary workaround, consider restricting access to the service listening on port 5001 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18013

Produtos afetados

Xen Mobile