Three critical vulnerabilities were discovered in two Citrix products.
Citrix has released a patch for three critical vulnerabilities found in two of its most popular products and is now urging users to apply the patch immediately.
Citrix ADC and Citrix Gateway were patched for three vulnerabilities. ADC is a load-balancing solution for cloud applications that are utilized by a large number of businesses to ensure high availability and performance.
Gateway, on the other hand, is an SSL VPN service that enables secure remote access with identity and access management features, and the linked vulnerability has been “widely deployed” in cloud and on-premises company servers.
Abusable under specific circumstances
These vulnerabilities are identified as CVE-2022-27510, CVE-2022-27513, and CVE-2022-25716. The former enables threat actors to circumvent authentication measures by utilizing alternative paths and channels. To exploit the vulnerability, Gateway must be configured as a VPN.
The second flaw is an insufficient data authenticity verification flaw that allows threat actors to remotely take control of a desktop endpoint via phishing. For this vulnerability, Gateway must be configured as a VPN, with RDP proxy functionality also configured.
The final vulnerability allows cybercriminals to circumvent brute force protection mechanisms for logins. To exploit the vulnerability, the appliance must be configured as a VPN or AAA virtual server with the “Max Login Attempts” setting enabled.
“Note that only appliances operating as a Gateway (appliances using the SSL VPN functionality or deployed as an ICA proxy with authentication enabled) are vulnerable to the first issue, which has a Critical severity rating,” explained Citrix.
“Affected customers of Citrix ADC and Citrix Gateway are advised to install the updated versions as soon as possible,” the company added.
The following is a list of affected software and their versions:
- Citrix ADC and Citrix Gateway 13.1 before 13.1-33.47
- Citrix ADC and Citrix Gateway 13.0 before 13.0-88.12
- Citrix ADC and Citrix Gateway 12.1 before 12.1.65.21
- Citrix ADC 12.1-FIPS before 12.1-55.289
- Citrix ADC 12.1-NDcPP before 12.1-55.289