CVE-2019-13609 - CRLF Vulnerability in Citrix License Server for Windows and VPX

Related Vulnerabilities: CVE-2019-13609  

Description of Problem

A Carriage Return Line Feed (CRLF) injection vulnerability has been identified in Citrix License Server for Windows and VPX that could allow an unauthenticated attacker to bypass authentication and allow a malicious website to read or modify license server data of an existing logged on session.

This vulnerability has been assigned the following CVE number:

• CVE-2019-13609: CRLF Vulnerability in License Server for Windows and VPX

This vulnerability affects the following Citrix License Server versions:

• Citrix License Server for Windows earlier than 11.15.0.0 Build 27000.

• Citrix License Server VPX all supported versions.  

 

Mitigating Factors

If access to admin console is restricted to trusted network the risk is reduced.

Security considerations for the admin console interface can be found at the following URL:

https://docs.citrix.com/en-us/licensing/current-release/getting-started.html 

Under security considerations

"Configure the License Server environment so that only authorized administrators on a trusted network can access the Licensing Administration Console port. You achieve this outcome by using an appropriately configured network or host-based firewall."

 

What Customers Should Do

The CRLF vulnerability has been addressed in the following version:

• Citrix License Server for Windows version 11.15.0.0 Build 27000 and newer. 

Customers with Citrix License Server VPX will need to deploy the Windows version for the fix.

Citrix recommends that customers upgrade their Citrix License Server deployments to this version or later.

The updates can be obtained from the following location:

https://www.citrix.com/downloads/licensing/

Acknowledgements

Citrix thanks Vahagn Vardanyan for working with us to protect Citrix customers.

What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.

Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html

Reporting Security Vulnerabilities

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For guidance on how to report security-related issues to Citrix, please see the following document: CTX081743 – Reporting Security Issues to Citrix

Changelog

Date  Change
27th August 2019 Initial Publication
28th August 2019 Updated "Applicable Products" section to include Licensing