Hundreds of Citrix NetScaler ADC and Gateway Servers Hacked in Major Cyber Attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-24489 | Unauthenticated RCE in Citrix ShareFile Storage Zones Controller (CVE-2023-24489) CVE-2023-24489 is an improper access control flaw (CWE-284), rated critical at CVSS 9.8, in the customer-managed Citrix Content Collaboration ShareFile storage zones controller. It can be triggered remotely over the network by an unauthenticated attacker with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N). A successful attack allows the attacker to remotely compromise the customer-managed storage zones controller — described in vendor-adjacent coverage as remote code execution — giving control of the server that stores and syncs that organization's ShareFile files. Only organizations that self-host customer-managed storage zones controllers are affected; the vendor-managed (cloud) ShareFile service is not listed as affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2023-08-16, EPSS assigns a 97.3% probability of exploitation within 30 days (100th percentile), and the vendor urged customers to shut down or take unpatched controllers offline; ransomware use is not yet confirmed. Do: Apply the fix specified in the Citrix/ShareFile security bulletin by upgrading every customer-managed storage zones controller to the vendor's patched release, and follow vendor guidance to shut down or take offline any controller that cannot be patched immediately. Check whether controllers are internet-exposed and hunt for signs of compromise (unexpected files, processes, or webshells on storage zones), since the flaw is in the KEV catalog and ransomware use has not been ruled out. | 9.8 | 97% | KEV |
| moderate≈ thousands of internet-exposed customer-managed storage zone controllers (order-of-magnitude estimate) | |
| CVE-2023-3519 | Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations. Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream… |
Full article327 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 03, 2023Vulnerability / Cyber Threat
Hundreds of Citrix NetScaler ADC and Gateway servers have been breached by malicious actors to deploy web shells, according to the Shadowserver Foundation.
The non-profit said the attacks take advantage of CVE-2023-3519, a critical code injection vulnerability that could lead to unauthenticated remote code execution.
The flaw, patched by Citrix last month, carries a CVSS score of 9.8.
The largest number of impacted IP addresses are based in Germany, followed by France, Switzerland, Italy, Sweden, Spain, Japan, China, Austria, and Brazil.
The exploitation of CVE-2023-3519 to deploy web shells was previously disclosed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which said the attack was directed against an unnamed critical infrastructure organization in June 2023.
The disclosure comes as GreyNoise said it detected three IP addresses attempting to exploit CVE-2023-24489 (CVSS score: 9.1), another critical flaw in Citrix ShareFile software that allows for unauthenticated arbitrary file upload and remote code execution.
The issue has been addressed in ShareFile storage zones controller version 5.11.24 and later.
Attack surface management firm Assetnote, which discovered and reported the bug, traced it to a simpler version of a padding oracle attack.
"[Cipher Block Chaining] mode and PKCS#7 padding are the default values for AES encryption in .NET," security researcher Dylan Pindur said.
"Look at how it behaves when invalid versus valid padding is provided. Does it result in an error? Are the errors different? Does it take longer or shorter to process? All of these can lead to a potential padding oracle attack."
Update
The Shadowserver Foundation, in an update shared on August 7, 2023, said it identified close to 7,000 vulnerable, unpatched NetScaler ADC and Gateway instances online and that CVE-2023-3519 is being exploited to drop PHP web shells on vulnerable servers for remote access.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/08/hundreds-of-citrix-netscaler-adc-and.html