Denial of service in Citrix License Server - CVE-2016-6273

 

Denial of service in Citrix License Server - CVE-2016-6273

Published: October 13, 2016 / Updated: October 14, 2016


Vulnerability identifier: #VU973
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6273
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause DoS conditions on the target system.
The weakness occurs in Citrix Licence Server and exists due to access control error that allow attackers to trigger the affected server to crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

Citrix License Server

How to mitigate CVE-2016-6273

Update to version 11.14.0.1 or later.
https://www.citrix.com/downloads/licensing/license-server/license-server-version-111401-for-windows.html#ctx-dl-eula


External References

Related Security Bulletins