CVE-2017-6316
CRITICAL KEVCitrix NetScaler SD-WAN <v9.1.2.26.561201 - Command Injection
Title source: llmExploitation Summary
CVE-2017-6316 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022. EIP tracks 2 public exploits from researchers including xort.
AI-analyzed exploit summary This Metasploit module exploits a remote command injection vulnerability in Citrix SD-WAN appliances (version <= 9.1.2.26.561201) via the CGISESSID cookie parameter. It allows unauthenticated remote code execution by injecting commands into the cookie, which are then executed by the system.
Description
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
Exploits (2)
This Metasploit module exploits a remote command injection vulnerability in Citrix SD-WAN appliances (version <= 9.1.2.26.561201) via the CGISESSID cookie parameter. It allows unauthenticated remote code execution by injecting commands into the cookie, which are then executed by the system.
This exploit leverages a command injection vulnerability in the `CAKEPHP` cookie parameter of the login.cgi endpoint. The `sleep 10` command demonstrates arbitrary command execution, which can be replaced with a reverse shell or other payloads.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H