Issue
XenMobile Server 10.14 and 10.15 use an OpenSSH version that is vulnerable to the following security issues: CVE-2023-48795, CVE-2023-51384, and CVE-2023-51385. These CVEs may be reported by customer vulnerability scanners against the XenMobile Server appliance.
Environment
Resolution
Citrix recommends upgrading XenMobile Server to a version that contains the OpenSSH fixes for CVE-2023-48795, CVE-2023-51384, and CVE-2023-51385:
After upgrading, re-run your vulnerability scans to confirm that the OpenSSH CVEs are no longer reported. For details about the changes and fixed issues in these releases, see the XenMobile Server 10.15 and 10.16 release notes.
XenMobile Server 10.14 and 10.15 are vulnerable to CVE-2023-48795,CVE-2023-51384,abd CVE-2023-5138.
To upgrade to 10.16 or 10.15 with RP 8+ is the final solution.
XenMobile server fix for CVE-2023-48795,CVE-2023-51384, and CVE-2023-51385