← Vulnerability feed

Vulnerability record · CVE-2017-6316 · published 20 July 2017

CVE-2017-6316: Citrix NetScaler SD-WAN cookie flaw allows root command execution

Citrix · Netscaler Sd Wan

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 accept a crafted CGISESSID cookie (CAKEPHP on older CloudBridge devices) that lets a remote attacker run arbitrary shell commands as root. The flaw is trivially reachable over the network with no credentials or user interaction, and it is listed in CISA KEV, so it matters to any organization still running the affected SD-WAN appliances.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 73% · top 0.6%
9.8CVSS 3.1 base score, v2 10.0
73%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote root command execution, confirmed in CISA KEV with very high EPSS and public exploit code.

What it is

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 accept a crafted CGISESSID cookie (CAKEPHP on older CloudBridge devices) that lets a remote attacker run arbitrary shell commands as root. The flaw is trivially reachable over the network with no credentials or user interaction, and it is listed in CISA KEV, so it matters to any organization still running the affected SD-WAN appliances.

Impact

An unauthenticated remote attacker gains root-level command execution on the SD-WAN appliance, giving full control of the device and any traffic or credentials it handles.

Attack surface

Reachable over the network via HTTP requests carrying a malicious CGISESSID (or CAKEPHP) cookie; the CVSS vector shows no privileges and no user interaction required.

Exploitation

CVE-2017-6316 is in CISA KEV with a 30-day EPSS probability of about 0.726 (99.4th percentile), and public Exploit-DB entries exist, so exploitation is confirmed and widely feasible.

What to do

  • Apply the Citrix update referenced in CTX225990 to move past v9.1.2.26.561201.
  • If patching is not immediately possible, restrict management and web interface access to trusted networks only.
  • Rotate any credentials or keys stored on or passing through the appliance, since root compromise exposes them.
  • Monitor Citrix advisories for the affected product line and confirm the exact fixed build before closing the finding.

Detection

  • Alert on HTTP requests to the SD-WAN web interface containing CGISESSID or CAKEPHP cookies with unusual or shell-like values.
  • Monitor for unexpected shell or command execution processes spawned by the web server on SD-WAN appliances.
  • Review appliance logs for anomalous outbound connections or new accounts following web requests from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-6316 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Citrix Multiple Products Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/99943 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039019 Broken LinkThird Party AdvisoryVDB Entry
https://support.citrix.com/article/CTX225990 Permissions Required
https://www.exploit-db.com/exploits/42345/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42346/ Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/99943 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039019 Broken LinkThird Party AdvisoryVDB Entry
https://support.citrix.com/article/CTX225990 Permissions Required
https://www.exploit-db.com/exploits/42345/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42346/ Third Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6316 US Government Resource

Track CVE-2017-6316 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12989Citrix SD-WAN and NetScaler SD-WAN SQL injectionCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 are vulnerable to SQL injection. The flaw is remotely reachable without …KEVEPSS 95%analysed8.8CVE-2019-12991Citrix SD-WAN and NetScaler SD-WAN command injection via input validation flawCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 fail to properly validate input, allowing OS command injection (CWE-78).…KEVEPSS 74%analysed9.8CVE-2019-12990Citrix netscaler sd-wan path traversal vulnerabilityCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.EPSS 39%9.8CVE-2019-12985Citrix netscaler sd-wan os command injection vulnerabilityCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).EPSS 40%9.8CVE-2019-12986Citrix netscaler sd-wan os command injection vulnerabilityCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).EPSS 40%9.8CVE-2019-12987Citrix netscaler sd-wan os command injection vulnerabilityCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).EPSS 43%9.8CVE-2019-12988Citrix netscaler sd-wan os command injection vulnerabilityCitrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).EPSS 43%9.8CVE-2018-17445Citrix netscaler sd-wan command injection vulnerabilityA Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2017-6316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.