PT-2021-7014 · Citrix · Citrix Xenmobile Server

Tsungshu Chiu

·

Published

2021-12-01

·

Updated

2022-07-12

·

CVE-2021-44520

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Citrix XenMobile Server versions through 10.12 RP9
Description The issue is related to insufficient access control in the Citrix XenMobile Server, which can be exploited to execute arbitrary code with root privileges. This can be done remotely. The vulnerability is described as an Authenticated Command Injection, leading to remote code execution with root privileges.
Recommendations For versions through 10.12 RP9, update to a version that includes the fix for this issue to prevent remote code execution with root privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02969
CVE-2021-44520

Affected Products

Citrix Xenmobile Server