CVE-2023-6184
Citrix Virtual Delivery Agent (VDA) vulnerability analysis and mitigation

Overview

CVE-2023-6184 is a Cross-Site Scripting (XSS) vulnerability discovered in Citrix Session Recording. Initially reported in late 2023, this vulnerability was found to be more severe than initially assessed, as it actually allows for Remote Code Execution (RCE) through insecure .NET remoting configurations that enable insecure deserialization (Assetnote Research).

Technical details

The vulnerability exists in the /SessionRecordingBroker endpoint of Citrix Session Recording, which exposes SOAP endpoints using System Runtime Remoting. The configuration includes typeFilterLevel="Full", which removes restrictions on the types of objects that can be passed. The vulnerability can be exploited through SOAP-formatted payloads, requiring specific conditions including POST or M-POST HTTP verbs and non-empty SOAPAction headers. The CVSS v3.1 base score is rated at 5.0 (MEDIUM) by Citrix, with a vector of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N, though NIST rates it higher at 7.2 (HIGH) (NVD).

Impact

When successfully exploited, this vulnerability allows attackers to achieve Remote Code Execution on the affected system. While initially classified as a Cross-Site Scripting vulnerability, security researchers demonstrated that it could lead to full system compromise through .NET deserialization attacks (Assetnote Research).

Mitigation and workarounds

Citrix has released security updates to address this vulnerability. Organizations running affected versions of Citrix Session Recording should upgrade to the latest version that includes the security fixes (Citrix Advisory).

Additional resources


SourceThis report was generated using AI

Related Citrix Virtual Delivery Agent (VDA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-6151HIGH8.5
  • Citrix Virtual Delivery Agent (VDA)Citrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
NoYesJul 10, 2024
CVE-2025-6759HIGH7.3
  • Citrix Virtual Delivery Agent (VDA)Citrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
NoYesJul 08, 2025
CVE-2023-6184HIGH7.2
  • Citrix Virtual Delivery Agent (VDA)Citrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
NoYesJan 18, 2024
CVE-2024-8069MEDIUM5.1
  • Citrix Virtual Delivery Agent (VDA)Citrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
YesYesNov 12, 2024
CVE-2024-8068MEDIUM5.1
  • Citrix Virtual Delivery Agent (VDA)Citrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
YesYesNov 12, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management