CVE-2018-14007
Description
Citrix XenServer 7.1 and newer allows Directory Traversal.
In plain language
AI Act nowCVE-2018-14007 is a serious directory “address guessing” flaw in Citrix XenServer 7.1+ that lets an attacker read or alter files if they can reach the vulnerable service; typical small businesses running these systems should act now to update.
CVE-2018-14007 is a Directory Traversal weakness in Citrix XenServer 7.1 and newer, allowing attackers to escape intended paths and access or modify files via crafted inputs to a vulnerable component; keep this in the highest-priority patch window.
What to do now
- Check whether you run Citrix XenServer 7.1 or newer (and whether the related Linux environment is in scope for this fix).
- Confirm your current Debian version and patch level (and whether you’re using the referenced Citrix remediation path for XenServer).
- Upgrade Debian to 4.19.67-2+deb10u2 or later.
- If you cannot patch immediately, contact your vendor support for an interim mitigation plan referenced by Citrix (CTX236548) and ensure the vulnerable interface is not exposed beyond your trusted network.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-14007 and every CVE in our database. Create a free account — no credit card required.
Create Free Account