Independent security research by Jakob Wolffhechel that summarizes their attempt to responsibly disclose vulnerabilities that were discovered in Citrix XenServer, XCP-ng, & XAPI-based Hypervisor.
Link: https://shittrix.moksha.dk/
Summary:
Critical findings (CVSS 9.1 - 9.9) 5 (3 x 9.9, 2 x 9.1) - 5
High findings (CVSS 7.0 - 8.9) - 28
Medium findings (CVSS 4.0 - 6.9) - 46
Low findings (CVSS 2.0 - 3.9) - 10
Affected products
- Citrix XenServer / Citrix Hypervisor - all versions, commercial product of Cloud Software Group
- XCP-ng - all versions, open-source downstream maintained by Vates
- Any XAPI-based hypervisor distribution
Downstream / collateral impact
- Storage arrays (NetApp, Dell EMC, Pure, HPE): silent protocol injection through the hypervisor as proxy. Indistinguishable from normal storage I/O.
- Management orchestrators (Xen Orchestra, CloudStack, OpenStack): trust XAPI metadata that is attacker-controlled.
- Backup systems: trust XAPI metadata, can be tricked into backing up attacker-chosen disks.
- Monitoring systems: ingest XAPI metadata as ground truth; can be poisoned.
- Cross-hypervisor platforms on shared storage: Proxmox, VMware, Nutanix VMs readable from an XAPI host on the same backing storage.