Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Vulnerability in Citrix XenServer Could Result in Information Disclosure (CTX201717)

Information

Severity

Severity

Medium

Family

Family

Citrix Xenserver Local Security Checks

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

8 years ago

Modified

Modified

5 years ago

Summary

A vulnerability has been identified in Citrix XenServer which could, if exploited, allow a malicious administrator of an HVM guest VM to obtain meta-data about their own VM. Citrix is presently unaware of any meta-data that might be leaked that would be of value to a malicious guest administrator. In non-default configurations, where the RTL8139 guest network device has been configured to enable offload and the Citrix PV guest drivers are not active, it may also be possible for a remote attacker to obtain information from the HVM guest.

Affected Software

Affected Software

This issue affects all supported versions of Citrix XenServer up to and including Citrix XenServer 6.5 Service Pack 1.

Detection Method

Detection Method

Check the installed hotfixes

Solution

Solution

Apply the hotfix referenced in the advisory.

Common Vulnerabilities and Exposures (CVE)