ZeroHour

CVE-2022-27518

KEVlarge

Unauthenticated RCE/Authentication Bypass in Citrix ADC and Gateway

CISA: Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2022-27518 is a critical flaw in Citrix Application Delivery Controller (ADC) and Gateway firmware that permits unauthenticated remote arbitrary code execution, which CISA characterizes as an authentication bypass. It is triggered remotely over the network with no credentials, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N, score 9.8), so any affected appliance with an internet-reachable interface is a potential target. A successful attacker gains code execution on the appliance and access to sensitive resources, which is especially dangerous on VPN gateway and load-balancing deployments that front-door enterprise networks. All organizations running Citrix ADC or Gateway appliances are potentially affected, with internet-exposed devices at greatest risk. The flaw is being actively exploited in the wild, including by state-sponsored actors; it was added to CISA KEV on 2022-12-13 and Citrix and the NSA publicly urged admins to patch, though no public proof-of-concept is known.

What to do: Apply the fixed firmware updates per Citrix's vendor instructions immediately, prioritizing internet-facing ADC and Gateway appliances, since the flaw is in CISA KEV and actively exploited by state-sponsored actors. Until patched, restrict or shield appliance interfaces where feasible, and review internet-exposed devices for indicators of compromise given the absence of a public PoC.

Affected
Citrix Application Delivery Controller (ADC) firmware
Citrix Gateway firmware
Estimated exposure
largetens of thousands of internet-exposed ADC/Gateway appliances, with thousands reported still unpatched after disclosure — Public internet-wide scans have repeatedly found tens of thousands of Citrix ADC/Gateway appliances exposed online, and contemporaneous reporting ('Thousands of Citrix Servers Still Unpatched') indicated thousands remained vulnerable,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated remote arbitrary code execution

CISA Known Exploited Vulnerability
Affected
Citrix Application Delivery Controller (ADC) and Gateway
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
application delivery controller firmware, gateway firmware
Weakness
CWE-664
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news