ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

State-sponsored attackers actively exploiting RCE in Citrix devices, patch ASAP! (CVE-2022-27518)

criticalVulnerability exploited in the wildimportance 60CVE-2022-27518

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27518
Unauthenticated RCE/Authentication Bypass in Citrix ADC and Gateway

CVE-2022-27518 is a critical flaw in Citrix Application Delivery Controller (ADC) and Gateway firmware that permits unauthenticated remote arbitrary code execution, which CISA characterizes as an authentication bypass. It is triggered remotely over the network with no credentials, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N, score 9.8), so any affected appliance with an internet-reachable interface is a potential target. A successful attacker gains code execution on the appliance and access to sensitive resources, which is especially dangerous on VPN gateway and load-balancing deployments that front-door enterprise networks. All organizations running Citrix ADC or Gateway appliances are potentially affected, with internet-exposed devices at greatest risk. The flaw is being actively exploited in the wild, including by state-sponsored actors; it was added to CISA KEV on 2022-12-13 and Citrix and the NSA publicly urged admins to patch, though no public proof-of-concept is known.

Do: Apply the fixed firmware updates per Citrix's vendor instructions immediately, prioritizing internet-facing ADC and Gateway appliances, since the flaw is in CISA KEV and actively exploited by state-sponsored actors. Until patched, restrict or shield appliance interfaces where feasible, and review internet-exposed devices for indicators of compromise given the absence of a public PoC.

9.87% KEV
  • Citrix Application Delivery Controller (ADC) firmware
  • Citrix Gateway firmware
largetens of thousands of internet-exposed ADC/Gateway appliances, with thousands reported still unpatched after disclosure
Full article295 words · extracted from helpnetsecurity.com · click to collapse

An unauthenticated remote code execution flaw (CVE-2022-27518) is being leveraged by a Chinese state-sponsored group to compromise Citrix Application Delivery Controller (ADC) deployments, the US National Security Agency has warned. “Targeting Citrix ADCs can facilitate illegitimate access to targeted organizations by bypassing normal authentication controls.”

About CVE-2022-27518

CVE-2022-27518 stems from the vulnerable devices’ software failing to maintain control over a resource throughout its lifetime (creation, use, and release) and gives remote attackers the opportunity to execute arbitrary code (without prior authentication) on vulnerable appliances.

The zero-day flaw affects both Citrix ADC, which is usually leveraged for load balanced, secure remote access to Citrix Virtual Apps and Desktops applications, and Citrix Gateway, a secure remote access solution with identity and access management capabilities, which also provides single sign-on for variously hosted applications.

Citrix’s security bulletin lists the affected supported and unsupported versions, and notes that only customer-managed Citrix ADC and Citrix Gateway appliances require a swift update.

The company also lists a pre-condition for exploitation: only Citrix ADCs and Citrix Gateways that are configured as a SAML SP (service provider) or a SAML IdP (identity provider) are at risk, and should be upgraded post-haste.

In-the-wild exploitation

The NSA has published threat hunting guidance to help organizations investigate whether their Citrix ADC environments have been compromised, and have attributed observed attacks to APT5 (aka UNC2630, aka MANGANESE).

For over a decade, APT5 has been targeting and breaching organizations across multiple industries, but especially telecommunications and technology companies. The group has previously been known to exploit vulnerabilities in VPN products by Fortinet, Palo Alto Networks and Pulse Secure.

“Update to the latest Citrix release, check for compromise, and let us know if you find anything,” said NSA’s Cybersecurity Director Rob Joyce following the release of the guidance.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/12/13/cve-2022-27518-exploited/