7.5
CVSSv2

CVE-2016-5302

Published: 13/06/2016 Updated: 20/06/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.

Vulnerable Product Search on Vulmon Subscribe to Product

citrix xenserver

Vendor Advisories

Description of Problem A security vulnerability has been identified in XenServer 70 that may allow an attacker on the management network who is in possession of Active Directory credentials for an AD account that is not authorised to manage a XenServer host to compromise that host The following vulnerability has been addressed: CVE-2016-5302 (Low ...