CVE-2018-18013 describes a remote code execution vulnerability in Citrix XenMobile Server through version 10.8.0. The vulnerability stems from a service on port 5001 that accepts and deserializes unauthenticated raw serialized Java objects, leading to arbitrary code execution. This vulnerability is rated as High severity (CVSS 7.8), indicating a local attack vector with low complexity, requiring low privileges, and potentially leading to high impact on confidentiality, integrity, and availability. The vendor disputes this as a vulnerability, claiming internal firewall mitigation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.8.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.