XenMobile server fix for CVE-2023-48795,CVE-2023-51384, and CVE-2023-51385

book

Article ID: CTX691692

calendar_today

Updated On:

Description

Issue

XenMobile Server 10.14 and 10.15 use an OpenSSH version that is vulnerable to the following security issues: CVE-2023-48795, CVE-2023-51384, and CVE-2023-51385. These CVEs may be reported by customer vulnerability scanners against the XenMobile Server appliance.


Environment

  • Product: XenMobile Server (on-premises)
  • Versions affected: XenMobile Server 10.14 and 10.15 (pre–Rolling Patch 8)
  • Not applicable to: Citrix Endpoint Management (cloud service)


Resolution

Citrix recommends upgrading XenMobile Server to a version that contains the OpenSSH fixes for CVE-2023-48795, CVE-2023-51384, and CVE-2023-51385:

  • Upgrade to XenMobile Server 10.16 (current release), or
  • If remaining on 10.15, upgrade to XenMobile Server 10.15 Rolling Patch 8 or later.


After upgrading, re-run your vulnerability scans to confirm that the OpenSSH CVEs are no longer reported. For details about the changes and fixed issues in these releases, see the XenMobile Server 10.15 and 10.16 release notes.

 

 

 

XenMobile Server 10.14 and 10.15 are vulnerable to CVE-2023-48795,CVE-2023-51384,abd CVE-2023-5138.

To upgrade to 10.16 or 10.15 with RP 8+ is the final solution.

 

 

Issue/Introduction

XenMobile server fix for CVE-2023-48795,CVE-2023-51384, and CVE-2023-51385