A Carriage Return Line Feed (CRLF) injection vulnerability has been identified in Citrix License Server for Windows and VPX that could allow an unauthenticated attacker to bypass authentication and allow a malicious website to read or modify license server data of an existing logged on session.
This vulnerability has been assigned the following CVE number:
• CVE-2019-13609: CRLF Vulnerability in License Server for Windows and VPX
This vulnerability affects the following Citrix License Server versions:
• Citrix License Server for Windows earlier than 11.15.0.0 Build 27000.
• Citrix License Server VPX all supported versions.
If access to admin console is restricted to trusted network the risk is reduced.
Security considerations for the admin console interface can be found at the following URL:
https://docs.citrix.com/en-us/licensing/current-release/getting-started.html
Under security considerations
"Configure the License Server environment so that only authorized administrators on a trusted network can access the Licensing Administration Console port. You achieve this outcome by using an appropriately configured network or host-based firewall."
The CRLF vulnerability has been addressed in the following version:
• Citrix License Server for Windows version 11.15.0.0 Build 27000 and newer.
Customers with Citrix License Server VPX will need to deploy the Windows version for the fix.
Citrix recommends that customers upgrade their Citrix License Server deployments to this version or later.
The updates can be obtained from the following location:
Citrix thanks Vahagn Vardanyan for working with us to protect Citrix customers.
Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html.
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For guidance on how to report security-related issues to Citrix, please see the following document: CTX081743 – Reporting Security Issues to Citrix
Date | Change |
27th August 2019 | Initial Publication |
28th August 2019 | Updated "Applicable Products" section to include Licensing |