CVE

NetScaler SD-WAN RCE (CVE-2017-6316)

Flag Citrix NetScaler SD-WAN hosts for CVE-2017-6316 by parsing /rN-N-N-N-N/ from GET /. FIXED floor 9.1.2.26.561202. No cookie cmd inject.

AuthorTrickest
100%

Notes on this workflow

CVE-2017-6316 — Citrix NetScaler SD-WAN (CloudBridge) Cmd Injection

What this checks: whether a Citrix NetScaler SD-WAN (CloudBridge) host runs a version affected by unauth cookie command injection (root RCE). Read-only: it fingerprints Citrix NetScaler SD-WAN (CloudBridge) and reads the version, no exploitation.

3. Detection — reads the Citrix NetScaler SD-WAN (CloudBridge) version from the product's default response and version banner, compares to after 9.1.2.26.561201 (build 561201 and earlier are vulnerable). Flags vulnerable on an affected build. No exploitation.

1. Target List — paste your Citrix NetScaler SD-WAN (CloudBridge) URLs here, one per line (e.g. https://host.example.com).

Overview

This workflow finds Citrix NetScaler SD-WAN (CloudBridge) and sorts each host by whether its build falls below the CVE-2017-6316 FIXED floor. CVE-2017-6316 is a pre-auth command injection path on vulnerable SD-WAN builds. This check never sends a cookie injection and never claims root RCE. Give it hostnames, IP addresses, or URLs you are authorised to test. The workflow GETs /, fingerprints the product from the response body, parses the version from an /rN-N-N-N-N/ path pattern in that body, and compares it to floor 9.1.2.26.561202. Every host comes back affected or not, so a fleet advisory becomes an evidenced list for exposure management. An affected row is a version signal only.

Run it on a schedule when edge SD-WAN appliances lag on maintenance builds. A CloudBridge still below 9.1.2.26.561202 is the reason the same fingerprint stays useful.

Pipeline

  1. Read the target list. Hosts, URLs, or ranges, one per line, become the scope.
  2. GET / on each host and fingerprint Citrix NetScaler SD-WAN / CloudBridge from product markers in the body.
  3. Parse the build from an /rN-N-N-N-N/ path pattern in the body and compare it to the CVE-2017-6316 FIXED floor 9.1.2.26.561202 in the graph.
  4. Collect the per-host rows: product match, version, vulnerable flag, and any fetch error.
  5. Emit the summary counts: hosts checked, product hits, vulnerable, and errors.

Inputs

  • Target scope. Hostnames, IP addresses, CIDR ranges, or URLs, one per line. Full URLs and host:port entries work too, since the workflow normalizes each into a bare host. Point it at scope you are authorised to test.

Outputs

  • results.jsonl. One row per host: URL, whether SD-WAN was detected, the version read, the vulnerable flag, and detail text.
  • findings.jsonl. The same per-host verdict shaped for triage, with severity set from the vulnerable flag.
  • summary.json. Counts across the list: targets, product hits, vulnerable, and errors, plus the detection notes from the graph.

Integrations

  • HTTP. Unauthenticated GET of / only. No cookie command injection and no root RCE confirm.

Sample output

The records below are illustrative and do not come from a real run. They show one SD-WAN host below the CVE-2017-6316 floor, one at or above it, and one host that is not the product.

urlis_productproduct_versionvulnerabledetail
https://sdwan.example.comtrue9.1.2.26.561201truebelow fixed release 9.1.2.26.561202
https://sdwan.example.orgtrue9.1.2.26.561202falseat or above fixed release
https://shop.example.netfalsenullfalsenot identified as Citrix NetScaler SD-WAN
{"cve": "CVE-2017-6316", "total_targets": 3, "product_detected": 2, "vulnerable": 1, "errors": 0}

FAQ

Which NetScaler SD-WAN versions does this flag?

Builds below floor 9.1.2.26.561202, the single FIXED floor coded in the graph. The compare uses the /rN-N-N-N-N/ build string the / response itself served.

No. The check only GETs / and parses the version path from the body. It does not send a cookie injection and it does not confirm root RCE.

Is this check safe on production?

Yes. It is a read-only unauthenticated GET of the public root page. It does not authenticate or inject a command.

Does the check need credentials?

No. It fingerprints the public product page the way an external scanner would.

What is CVE-2017-6316?

Pre-auth command injection in Citrix NetScaler SD-WAN (CloudBridge) on vulnerable builds. This workflow maps hosts to that CVE by version exposure only.

Get a personalized demo

See Trickest in Action

A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.