CVE-2018-18014
published 2018-10-24CVE-2018-18014: * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private…
PriorityP421medium4.8CVSS 3.1
AVLACLPRLUIRSUCLILAL
EPSS
0.48%
38.1th percentile
* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | xenmobile_server | <= 10.8.0 | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2018-18014: * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to
vendor_citrix·2018-10-24·CVSS 4.8
CVE-2018-18014 [MEDIUM] CWE-287 CVE-2018-18014: * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to
CVE-2018-18014: * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.
GHSA
GHSA-cmw7-f487-jf92: ** DISPUTED *** Lack of authentication in Citrix Xen Mobile through 10
ghsa_unreviewed·2022-05-13
CVE-2018-18014 [HIGH] CWE-287 GHSA-cmw7-f487-jf92: ** DISPUTED *** Lack of authentication in Citrix Xen Mobile through 10
** DISPUTED *** Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-24
Published