Denial of service in Citrix License Server - CVE-2016-6273

 

Denial of service in Citrix License Server - CVE-2016-6273

Published: October 13, 2016 / Updated: October 14, 2016


Vulnerability identifier: #VU973
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-6273
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Citrix
Affected software:
Citrix License Server

Detailed vulnerability description

The vulnerability allows a remote unauthenticated user to cause DoS conditions on the target system.
The weakness occurs in Citrix Licence Server and exists due to access control error that allow attackers to trigger the affected server to crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

How to mitigate CVE-2016-6273

Update to version 11.14.0.1 or later.
https://www.citrix.com/downloads/licensing/license-server/license-server-version-111401-for-windows.html#ctx-dl-eula

Sources