Loading
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.
Use Citrix vendor hub and Netscaler Sd-Wan product page to widen CVE-2017-6316 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-12989, CVE-2019-12991 and CVE-2019-12990 for nearby disclosures in the same product family.