Vulnerability record · CVE-2017-6316 · published 20 July 2017
CVE-2017-6316: Citrix NetScaler SD-WAN cookie flaw allows root command execution
Citrix · Netscaler Sd Wan
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 accept a crafted CGISESSID cookie (CAKEPHP on older CloudBridge devices) that lets a remote attacker run arbitrary shell commands as root. The flaw is trivially reachable over the network with no credentials or user interaction, and it is listed in CISA KEV, so it matters to any organization still running the affected SD-WAN appliances.
Description
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution, confirmed in CISA KEV with very high EPSS and public exploit code.
What it is
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 accept a crafted CGISESSID cookie (CAKEPHP on older CloudBridge devices) that lets a remote attacker run arbitrary shell commands as root. The flaw is trivially reachable over the network with no credentials or user interaction, and it is listed in CISA KEV, so it matters to any organization still running the affected SD-WAN appliances.
Impact
An unauthenticated remote attacker gains root-level command execution on the SD-WAN appliance, giving full control of the device and any traffic or credentials it handles.
Attack surface
Reachable over the network via HTTP requests carrying a malicious CGISESSID (or CAKEPHP) cookie; the CVSS vector shows no privileges and no user interaction required.
Exploitation
CVE-2017-6316 is in CISA KEV with a 30-day EPSS probability of about 0.726 (99.4th percentile), and public Exploit-DB entries exist, so exploitation is confirmed and widely feasible.
What to do
- Apply the Citrix update referenced in CTX225990 to move past v9.1.2.26.561201.
- If patching is not immediately possible, restrict management and web interface access to trusted networks only.
- Rotate any credentials or keys stored on or passing through the appliance, since root compromise exposes them.
- Monitor Citrix advisories for the affected product line and confirm the exact fixed build before closing the finding.
Detection
- Alert on HTTP requests to the SD-WAN web interface containing CGISESSID or CAKEPHP cookies with unusual or shell-like values.
- Monitor for unexpected shell or command execution processes spawned by the web server on SD-WAN appliances.
- Review appliance logs for anomalous outbound connections or new accounts following web requests from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6316 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Citrix Multiple Products Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/99943 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039019 | Broken LinkThird Party AdvisoryVDB Entry |
| https://support.citrix.com/article/CTX225990 | Permissions Required |
| https://www.exploit-db.com/exploits/42345/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42346/ | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/99943 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039019 | Broken LinkThird Party AdvisoryVDB Entry |
| https://support.citrix.com/article/CTX225990 | Permissions Required |
| https://www.exploit-db.com/exploits/42345/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42346/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6316 | US Government Resource |
Track CVE-2017-6316 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.