ZeroHour
Security Affairspublished ()ingested @securityaffairs

Hackers are scanning the web for vulnerable Citrix systems

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-19781
Unauthenticated path traversal RCE in Citrix ADC, Gateway, and SD-WAN WANOP

CVE-2019-19781 is a path-traversal flaw (classified CWE-22, though CISA's description calls it unspecified) in Citrix ADC (formerly NetScaler ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances that lets an unauthenticated remote attacker traverse directories via crafted requests and execute arbitrary commands on the appliance, typically with root privileges. It is triggered by sending specially crafted directory-traversal requests (crafted URLs/requests to the appliance's management or VPN endpoints), which lets the attacker write files and run commands with no credentials. Successful exploitation yields arbitrary code execution on the appliance, enabling theft of VPN/ADC credentials, lateral movement into the corporate network, and installation of persistent backdoors. Any organization running affected ADC, Gateway, or SD-WAN WANOP firmware is affected, with internet-facing gateways used for remote access at the highest risk. Exploitation is confirmed in the wild: the vulnerability is on CISA's KEV (added 2021-11-03) with known ransomware use, EPSS assigns near-certain (100.0%) probability of exploitation within 30 days, and no public PoC is listed despite confirmed abuse.

Do: Upgrade Citrix ADC, Gateway, and SD-WAN WANOP appliances to the fixed firmware builds listed in Citrix advisory CTX267020; if patching cannot be done immediately, apply Citrix's published interim mitigation and restrict internet exposure to the appliance. Because exploitation grants root code execution and persistence, after patching hunt for indicators of compromise (unexpected nsroot account, modified system files, crontab/scheduled entries), kill all active and inactive sessions, and rotate appliance and VPN credentials. Prioritize internet-facing gateways and comply with CISA's required action to apply vendor updates.

9.8100% KEV ransomware
  • Citrix Application Delivery Controller (ADC) Supported ADC firmware lines in effect at disclosure (10.5, 11.0, 11.1, 12.0, 12.1, 13.0) prior to patched builds, per Citrix advisory CTX267020; exact builds n
  • Citrix Gateway Supported Gateway firmware lines (sharing the ADC codebase, same affected releases 10.5-13.0) prior to patched builds, per Citrix advisory; exact builds not spe
  • Citrix SD-WAN WANOP Appliance Affected appliance models (4000, 4100, 5000, 5100) running pre-patch firmware in the 10.2.1-11.4.1 range, per Citrix advisory; exact builds not specified in the
massroughly 80,000-100,000+ internet-exposed Citrix ADC/Gateway appliances at the time of disclosure, with a far larger total installed base (including…
CVE-2020-8195
+1 in the same advisory: …8196
Information Disclosure (Improper Input Validation) in Citrix ADC, Gateway, SD-WAN WANOP

CVE-2020-8195 is an information disclosure vulnerability in Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models, rooted in improper input validation (CWE-20). An attacker can trigger the flaw by getting the affected appliance to process crafted or malformed input, causing it to disclose sensitive information that could support further attacks against the appliance or the environment behind it. Organizations running these Citrix edge appliances — particularly ADC/Gateway deployments handling application delivery and remote access, and enterprises using SD-WAN WANOP for WAN optimization — are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware association unknown), and EPSS assigns it a high 33.3% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CISA's required action is to apply updates per vendor instructions.

Do: Apply the latest patched firmware to Citrix ADC, Gateway, and SD-WAN WANOP appliances per Citrix's security bulletin — the exact affected version ranges and fixed releases are in the vendor advisory — prioritizing internet-facing devices, as required by the CISA KEV listing. Because this is an information disclosure flaw, review appliance logs and consider rotating credentials, secrets, or configuration data that may have been exposed. Inventory all ADC/Gateway/SD-WAN WANOP deployments, including appliances reachable only internally, and confirm each is running a fixed build.

6.5
group max
33% KEV PoC
  • Citrix Application Delivery Controller (ADC)
  • Citrix Gateway
  • Citrix SD-WAN WANOP Appliance (multiple models)
largeTens of thousands of internet-exposed appliances (roughly 80,000+ Citrix ADC/Gateway endpoints in public internet scans around the disclosure period), with a…
Full article359 words · extracted from securityaffairs.com · click to collapse

Threat actors are scanning the Internet for Citrix systems affected by the recently disclosed vulnerabilities.

This week Citrix has addressed 11 vulnerabilities affecting the ADC, Gateway, and SD-WAN WANOP networking products. The vulnerabilities could be exploited by attackers for local privilege escalation, to trigger a DoS condition, to bypass authorization, to get code injection, and to launch XSS attacks.

Some of the addressed flaws could be exploited only if the attackers have access to the targeted system and request user interaction, or other conditions must be verified. For this reason, Citrix believes the flaws are less likely to be exploited.

Citrix CISO, Fermin J. Serna, explained that, at least for the CTX276688, there are five important points to understand:

  • The latest patches fully resolve all the issues.
  • Of the 11 vulnerabilities, there are six possible attacks routes; five of those have barriers to exploitation.
  • We are not aware of any exploitation of these issues.
  • Citrix-managed Gateway service is not affected.
  • And finally, these vulnerabilities are not related to CVE-2019-19781.

Now, hackers are scanning the web for systems affected by the recently disclosed Citrix vulnerabilities.

Johannes Ullrich, the head of research at the SANS Technology Institute, confirmed that one of its honeypots set up to capture attacks attempting to exploit the recently disclosed flaw in the F5 Networks’ BIG-IP systems was targeted by hackers attempting to exploit two of the recent Citrix vulnerabilities.

“As of today, my F5 honeypot is getting hit by attempts to exploit two of the Citrix vulnerabilities disclosed this week.” reads the post published by the SANS Technology Institute.

“It is not clear exactly which CVE was assigned to which vulnerability, but the possible candidates are CVE-2020-8195, CVE-2020-8196, “

According to Ullrich, attacks aimed at downloading files and obtaining information attempting to trigger two information disclosure issues whose exploitation requires authentication on the IP address at which a Citrix ADC appliance can be accessed for management purposes.

The list of IPs that are scanning for this vulnerability along with the requests sent to the honeypots are available in here.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, CITRIX)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/105776/hacking/vulnerable-citrix-systems-scan.html