PT-2021-7039 · Citrix · Citrix Xenmobile Server

·

CVE-2021-44519

·

Published

2021-04-12

·

Updated

2022-12-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix XenMobile Server versions through 10.12 RP9
Description The issue exists due to incorrect restriction of the path name to a directory with limited access. This can allow a remote attacker to execute arbitrary code. The vulnerability is described as an Authenticated Directory Traversal vulnerability, leading to remote code execution.
Recommendations For versions through 10.12 RP9, update to a version that contains a fix for this issue to prevent remote code execution. As a temporary workaround, consider restricting access to sensitive directories to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03025
CVE-2021-44519

Affected Products

Citrix Xenmobile Server