Description of Problem
A Carriage Return Line Feed (CRLF) injection vulnerability has been identified in Citrix License Server for Windows and VPX that could allow an unauthenticated attacker to bypass authentication and allow a malicious website to read or modify license server data of an existing logged on session.
This vulnerability has been assigned the following CVE number:
• CVE-2019-13609: CRLF Vulnerability in License Server for Windows and VPX
This vulnerability affects the following Citrix License Server versions:
• Citrix License Server for Windows earlier than 11.15.0.0 Build 27000.
• Citrix License Server VPX all supported versions.
Mitigating Factors
If access to admin console is restricted to trusted network the risk is reduced.
Security considerations for the admin console interface can be found at the following URL:
https://docs.citrix.com/en-us/licensing/current-release/getting-started.html
Under security considerations
"Configure the License Server environment so that only authorized administrators on a trusted network can access the Licensing Administration Console port. You achieve this outcome by using an appropriately configured network or host-based firewall."
What Customers Should Do
The CRLF vulnerability has been addressed in the following version:
• Citrix License Server for Windows version 11.15.0.0 Build 27000 and newer.
Customers with Citrix License Server VPX will need to deploy the Windows version for the fix.
Citrix recommends that customers upgrade their Citrix License Server deployments to this version or later.
The updates can be obtained from the following location:
Acknowledgements
Citrix thanks Vahagn Vardanyan for working with us to protect Citrix customers.
What Citrix Is Doing
Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.
Obtaining Support on This Issue
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html.
Reporting Security Vulnerabilities
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For guidance on how to report security-related issues to Citrix, please see the following document: CTX081743 – Reporting Security Issues to Citrix
Changelog
Date | Change |
27th August 2019 | Initial Publication |
28th August 2019 | Updated "Applicable Products" section to include Licensing |