CVE-2017-6316

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/07/2017
Last modified:
22/10/2025

Description

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:* 9.1.2.26.561201 (including)