Citrix Hypervisor vulnerabilities: How to find affected assets
ID: 18bf9fd0-7916-523a-a69e-492258c8333a
STIX ID: report--18bf9fd0-7916-523a-a69e-492258c8333a
Feed Name: runZero Blog
Researchers disclosed 89 exploitable input-validation vulnerabilities across XAPI Map(String,String) fields in Citrix Hypervisor/XenServer and XCP-ng, allowing an authenticated vm-admin to gain host filesystem read/write, cross-VM data exfiltration, storage-protocol injection, cross-hypervisor lateral movement, and pool-wide compromise; the flaws affect all XAPI-based distributions (present since ~2006), carry a distribution of 5 critical/28 high/46 medium/10 low severities, have no CVE IDs yet, and researchers recommend full rebuilds since no vendor patches are currently available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
