ZeroHour
The Recordpublished ()ingested

In alerting about two Citrix bugs, CISA recommends immediate attention for one

highRansomware exploited in the wildimportance 60CVE-2023-6548CVE-2023-6549

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6548
+1 in the same advisory: …6549
Authenticated Code-Injection RCE in Citrix NetScaler ADC/Gateway

CVE-2023-6548 is a code injection flaw (CWE-94) in the management interface of Citrix NetScaler ADC and NetScaler Gateway that allows remote code execution. It is triggered when an attacker who can reach the appliance's NSIP, CLIP, or a SNIP with management interface access authenticates with valid low-privileged credentials and sends crafted input that the appliance turns into executable code. Successful exploitation yields authenticated remote code execution in the context of the management interface, with high impact on the confidentiality, integrity, and availability of the appliance. Affected organizations are those running Citrix NetScaler ADC or NetScaler Gateway appliances, particularly deployments whose management interfaces are reachable from less-trusted networks or shared with low-privileged users. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17 and urged immediate action, though no public proof-of-concept code is known and EPSS currently estimates a ~3.2% chance of exploitation within 30 days.

Do: Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the fixed builds in Citrix's security bulletin for CVE-2023-6548 (released alongside the companion CVE-2023-6546 NetScaler privilege-escalation fix), per CISA's KEV directive to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Reduce exposure by restricting management interface access on the NSIP, CLIP, and SNIPs to trusted admin networks and by removing or constraining low-privileged accounts that do not need management access. Review appliance authentication logs and configurations for unexpected logins or changes, since exploitation requires authenticated access to the management interface.

8.8
group max
3% KEV
  • Citrix NetScaler Application Delivery Controller (ADC)
  • Citrix NetScaler Gateway
large~tens of thousands of NetScaler appliances with reachable management interfaces (out of a very large global installed base)
Full article262 words · extracted from therecord.media · click to collapse

Two bugs in Citrix technology are drawing serious attention this week from the Cybersecurity and Infrastructure Security Agency.

CISA says federal agencies much patch one of the vulnerabilities — tagged as CVE-2023-6548 — by January 24. It’s one of the rare times the cyber agency has put a remediation date of less than three weeks on a vulnerability.

CISA did not respond to requests for comment about why the remediation timeline was shorter than most.

The other bug — listed as CVE-2023-6548 — must be fixed by February 7. CISA’s alerts are aimed at federal agencies but often serve as general warnings for the public.

The vulnerabilities are in Citrix’s NetScaler ADC and NetScaler Gateway, used for managing network traffic and remote access, respectively.

The feds issued a short alert Thursday after adding the two issues to its Known Exploited Vulnerabilities catalog on Wednesday. Citrix itself issued a bulletin on Tuesday.

CVE-2023-6548 is a “code injection vulnerability,” while CVE-2023-6549 allows for an attacker to overflow the memory buffer and knock the Citrix services offline, CISA said.

Throughout November and December, U.S. cybersecurity agencies warned of another vulnerability affecting NetScaler ADC and NetScaler Gateway devices known as “Citrix Bleed.” Ransomware gangs used the bug in multiple high-profile attacks on vulnerable devices exposed to the internet.

CISA Executive Assistant Director for Cybersecurity Eric Goldstein said more than 300 entities have been warned about their exposure to the issue. Boeing allowed agencies to use the attack it experienced as an example for how security teams should address the vulnerability.

Joe Warminsky contributed to this story.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-citrix-bugs-immediate-attention-for-one