Cyber Resilience

CVE-2017-6316

Citrix Netscaler Sd-Wan ≤ 9.1.2.26.561201

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
20 July 2017
Modified
21 April 2026
KEV Added
25 March 2022
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.73 99.4th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2017-6316 is a critical-severity an unspecified weakness vulnerability in Citrix Netscaler Sd-Wan. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Citrix NetScaler SD-WAN appliances through version 9.1.2.26.561201 contain a remote command execution flaw that permits unauthenticated attackers to run arbitrary shell commands as root by supplying a crafted CGISESSID cookie; the same issue previously affected CloudBridge devices under the cookie name CAKEPHP. The vulnerability received a CVSS v3 score of 9.8, reflecting network attack vector, low complexity, and no required privileges or user interaction.

An attacker with network access to the management interface can therefore achieve full system compromise simply by sending a malicious cookie value, bypassing all authentication controls and obtaining a root shell on the device.

Citrix addressed the issue in security bulletin CTX225990, while public exploit code has been published on Exploit-DB. The flaw affects the web management component and requires no special configuration beyond the default cookie handling present in the listed firmware versions.

EU & UK References

Vulnerability Data

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

CWE(s)
KEV Date Added
25 March 2022

Related Threats

CVEs Like This One

CVE-2019-12991Same product: Citrix Netscaler Sd-Wanboth on KEV
CVE-2019-12989Same product: Citrix Netscaler Sd-Wanboth on KEV
CVE-2020-8193Same vendor: Citrixboth on KEV
CVE-2024-8068Same vendor: Citrixboth on KEV
CVE-2023-4966Same vendor: Citrixboth on KEV
CVE-2020-8196Same vendor: Citrixboth on KEV
CVE-2019-11634Same vendor: Citrixboth on KEV
CVE-2023-3519Same vendor: Citrixboth on KEV
CVE-2025-6543Same vendor: Citrixboth on KEV
CVE-2020-8195Same vendor: Citrixboth on KEV

Affected Assets

citrix
netscaler sd-wan
≤ 9.1.2.26.561201

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References