Citrix XenServer Authentication Bypass Vulnerability
BID:38052
Info
Citrix XenServer Authentication Bypass Vulnerability
| Bugtraq ID: | 38052 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-0633 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Citrix XenServer 5.5 Citrix XenServer 5.0 Update 3 |
| Not Vulnerable: | |
Discussion
Citrix XenServer Authentication Bypass Vulnerability
Citrix XenServer is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to execute a subset of Xen API (XAPI) calls without proper authentication. Successful exploits may lead to other attacks.
This issue affects Citrix XenServer 5.0 and 5.5.
Citrix XenServer is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to execute a subset of Xen API (XAPI) calls without proper authentication. Successful exploits may lead to other attacks.
This issue affects Citrix XenServer 5.0 and 5.5.
Exploit / POC
Citrix XenServer Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
Citrix XenServer Authentication Bypass Vulnerability
Solution:
The vendor has released fixes. Please see the references for details.
Citrix XenServer 5.0 Update 3
Citrix XenServer 5.5
Solution:
The vendor has released fixes. Please see the references for details.
Citrix XenServer 5.0 Update 3
-
Citrix XS50EU3003.zip
http://support.citrix.com/servlet/KbServlet/download/22659-102-642197/ XS50EU3003.zip
Citrix XenServer 5.5
References
Citrix XenServer Authentication Bypass Vulnerability
References:
References: