Remote Code Execution Vulnerability in Xen Mobile by Citrix
CVE-2018-18013

7.8HIGH

Key Information:

Vendor
Citrix
Vendor
CVE Published:
24 October 2018

Summary

Xen Mobile versions up to 10.8.0 contain a security flaw due to a service listening on port 5001, which allows for unauthenticated input. This vulnerability permits attackers to send raw serialized Java objects that can be deserialized in memory, potentially leading to remote code execution. Although Citrix claims that the internal firewall mitigates these risks by restricting access to localhost, the potential for exploitation remains a concern for organizations using this software.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.