89 vulnerabilities in XAPI used by Citrix XenServer, XCP-ng & any XAPI-based hypervisor

Independent security research by Jakob Wolffhechel that summarizes their attempt to responsibly disclose vulnerabilities that were discovered in Citrix XenServer, XCP-ng, & XAPI-based Hypervisor.

Link: https://shittrix.moksha.dk/

Summary:

Critical findings (CVSS 9.1 - 9.9) 5 (3 x 9.9, 2 x 9.1) - 5
High findings (CVSS 7.0 - 8.9) - 28
Medium findings (CVSS 4.0 - 6.9) - 46
Low findings (CVSS 2.0 - 3.9) - 10

Affected products

  • Citrix XenServer / Citrix Hypervisor - all versions, commercial product of Cloud Software Group
  • XCP-ng - all versions, open-source downstream maintained by Vates
  • Any XAPI-based hypervisor distribution

Downstream / collateral impact

  • Storage arrays (NetApp, Dell EMC, Pure, HPE): silent protocol injection through the hypervisor as proxy. Indistinguishable from normal storage I/O.
  • Management orchestrators (Xen Orchestra, CloudStack, OpenStack): trust XAPI metadata that is attacker-controlled.
  • Backup systems: trust XAPI metadata, can be tricked into backing up attacker-chosen disks.
  • Monitoring systems: ingest XAPI metadata as ground truth; can be poisoned.
  • Cross-hypervisor platforms on shared storage: Proxmox, VMware, Nutanix VMs readable from an XAPI host on the same backing storage.
1 Like