QID 377779

QID 377779: Citrix XenServer Security Updates (CTX286756)

Several security issues have been identified: CVE-2020-29479 : An attacker with the ability to execute privileged mode code in a guest can compromise the host CVE-2020-29480 : An attacker with the ability to execute privileged mode code in a guest can read non-sensitive metadata about another guest. CVE-2020-29481 : An attacker with the ability to execute privileged mode code in a guest can read data previously shared, using the Xenstore API, between two other guests. CVE-2020-29482 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host. CVE-2020-29485 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host. CVE-2020-29486 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host or a selected other VM. CVE-2020-29487 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host. CVE-2020-29568 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host. CVE-2020-29569 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host. CVE-2020-29570 : An attacker with the ability to execute privileged mode code in a guest can perform a denial of service attack against the host.

Affected Products:
Citrix XenServer 7.1 LTSR, Citrix XenServer 7.0 Note: This QID will detect only for Citrix XenServer 7.1 LTSR ,Citrix XenServer 7.0

QID Detection Logic (Authenticated):
OS:Citrix XenServer
The QID checks if Hotfixes is applied on the vulnerable versions of Citrix XenServer.

Vulnerable version could allow privileged code running in a guest VM to compromise the host or cause a denial of service.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Hotfixes have been released for Citrix XenServer to address these issues. Refer to CTX286756 to obtain more information.

    Software Advisories
    Advisory ID Software Component Link
    CTX286756 URL Logo support.citrix.com/article/CTX286756/citrix-hypervisor-security-update