Citrix urges admins to patch these dangerous flaws immediately

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

Citrix has released a fix for three high-severity vulnerabilities discovered in two of its popular products, and is now urging users to apply the patch immediately.

The company has fixed three flaws found in Citrix ADC and Citrix Gateway. ADC is a load-balancing solution for cloud applications, apparently used by many enterprises to ensure uninterrupted availability and high performance. 

Gateway, on the other hand, is an SSL VPN service that enables secure remote access with identity and access management features, and the linked flaw has been “widely deployed” in the cloud or on-prem company servers. 

Abusable under specific circumstances

The flaws in question are tracked as CVE-2022-27510, CVE-2022-27513, and CVE-2022-25716. The former allows threat actors to bypass authentication measures using alternate paths and channels. To abuse the flaw, Gateway needs to be configured as VPN. 

The second vulnerability is an insufficient data authenticity verification flaw, which allows threat actors to take over a desktop endpoint remotely, via phishing. For this flaw, Gateway needs to be configured as VPN, with RDP proxy functionality configured, as well. 

The final flaw allows cybercriminals to bypass login brute force protection mechanisms. For the vulnerability to be used, the appliance needs to be configured as VPN, or AAA virtual server with “Max Login Attempts” configuration.

"Note that only appliances that are operating as a Gateway (appliances using the SSL VPN functionality or deployed as an ICA proxy with authentication enabled) are affected by the first issue, which is rated as a Critical severity vulnerability," Citrix explained.

"Affected customers of Citrix ADC and Citrix Gateway are recommended to install the relevant updated versions of Citrix ADC or Citrix Gateway as soon as possible," the company further added.

Here is the list of the affected software and its versions:

  • Citrix ADC and Citrix Gateway 13.1 before 13.1-33.47
  • Citrix ADC and Citrix Gateway 13.0 before 13.0-88.12
  • Citrix ADC and Citrix Gateway 12.1 before 12.1.65.21
  • Citrix ADC 12.1-FIPS before 12.1-55.289
  • Citrix ADC 12.1-NDcPP before 12.1-55.289

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
Security
Broadcom releases fixes for multiple VMware security flaws
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Cisco patches critical security issues, so update now
Latest in Pro
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
A person holding out their hand with a digital AI symbol.
Taking AI to the edge for smaller, smarter, and more secure applications
Someone looking at a marketing graph
Why ‘boring’ tech will be 2025's biggest marketing trend
TinEye website
I like this reverse image search service the most
Epos Expand Vision 5 Bundle main image
I tested the Epos Expand Vision 5 Bundle - read why this video conferencing solution is recommended
Latest in News
The Samsung Galaxy S21 series of phones lying face down.
Samsung announces One UI 7 is coming to older phones after all, but the launch is still a mess
Using Zipped files and folders in Windows 11
Windows 11 should soon be faster at extracting files from compressed ZIPs – and it’s about time, frankly
The player prepares for a fight in Metal Eden.
I loved the bits of Metal Eden that I played and soon you'll be able to try it too thanks to this upcoming free demo
Apple iPhone 16 Pro HANDS ON
The iPhone 18 might get a major chip upgrade after all
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Oppo Watch Mini X2 teaser
Oppo Watch X2 Mini teaser could be our first glimpse of the smaller OnePlus Watch 3