Description of Problem
A vulnerability has been identified in Citrix XenMobile Server that could permit an attacker to impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
The vulnerability has been assigned the following CVE number:
• CVE-2018-18571: Authentication Bypass Vulnerability in Citrix XenMobile Server.
This vulnerability affects the following products:
• Citrix XenMobile Server 10.9.0 before Rolling Patch 3.
• Citrix XenMobile Server 10.8.0 before Rolling Patch 6.
What Customers Should Do
Citrix recommends customers running Citrix XenMobile Server 10.9.0 upgrade to Rolling Patch 3 found at https://support.citrix.com/article/CTX249985 and Citrix XenMobile Server 10.8.0 upgrade to Rolling Patch 6 found at https://support.citrix.com/article/CTX250711.
Also, a newer version of Citrix XenMobile Server is now available: Citrix XenMobile Server version 10.10.0.7
Citrix strongly recommends that affected customers upgrade their XenMobile Servers to the new version. This new version can be obtained from the following location:
Citrix Product Downloads: https://www.citrix.com/downloads/citrix-endpoint-management/.
These issues have already been addressed in the Citrix Cloud service.
Windows device users who have upgraded to Citrix Endpoint Management 19.3.1, please reference the following article and recreate your Store device policy: https://support.citrix.com/article/CTX249857.
Acknowledgements
Citrix thanks Jonas of Danske Bank for working with us to protect Citrix customers.
What Citrix Is Doing
Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.
Obtaining Support on This Issue
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html.
Reporting Security Vulnerabilities
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For guidance on how to report security-related issues to Citrix, please see the following document: CTX081743 – Reporting Security Issues to Citrix
Changelog
| Date | Change |
| 26th April 2019 | Initial Publication |
| 30th April 2019 | Correction of MDM to MAM |