HC3 Sector Alert TLP White: Citrix Endpoint Management (CEM) AKA XenMobile Server Critical Vulnerabilities

August 13, 2020

The XenMobile application is used by many businesses, including those in the HPH sector, and enables businesses to manage employees’ mobile devices and mobile applications by controlling device security settings and updates. For example, a healthcare organization might use XenMobile to create an in-house app that allows physicians to view patient information on mobile devices. On August 11, 2020, Citrix released a security bulletin regarding a set of vulnerabilities in certain on-premises instances of Citrix Endpoint Management (CEM), often referred to as XenMobile Server. Some of these vulnerabilities are rated as critical severity and could allow unauthenticated attackers to take over XenMobile Servers following successful exploitation. Citrix recommends updating XenMobile deployments immediately.