Hackers Actively Exploiting Citrix ADC and Gateway Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22893 | Use-After-Free RCE in Ivanti Pulse Connect Secure License Services Ivanti Pulse Connect Secure, a widely deployed SSL VPN appliance, contains a use-after-free vulnerability in its license services. A remote, unauthenticated attacker can trigger the flaw via the license services and gain arbitrary code execution on the appliance, which is a high-value target because it terminates VPN sessions for enterprise networks. Any organization running an affected Pulse Connect Secure release is potentially affected; the source data does not specify exact version ranges, so administrators should compare their release against Ivanti's advisory. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and its 47.2% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Do: Apply the updates per Ivanti's instructions immediately, as CISA's required action specifies. Because exploited appliances have often retained persistent webshells/backdoors even after patching, also hunt for indicators of compromise (modified appliance files, unexpected processes or accounts) and follow Ivanti's remediation guidance rather than only installing the update. Until patched, restrict or closely monitor internet access to the appliance. | 10.0 | 47% | KEV ransomware |
| largetens of thousands of internet-exposed Pulse Connect Secure VPN appliances (order of magnitude ~10^4-10^5) | |
| CVE-2022-27518 | Unauthenticated RCE/Authentication Bypass in Citrix ADC and Gateway CVE-2022-27518 is a critical flaw in Citrix Application Delivery Controller (ADC) and Gateway firmware that permits unauthenticated remote arbitrary code execution, which CISA characterizes as an authentication bypass. It is triggered remotely over the network with no credentials, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N, score 9.8), so any affected appliance with an internet-reachable interface is a potential target. A successful attacker gains code execution on the appliance and access to sensitive resources, which is especially dangerous on VPN gateway and load-balancing deployments that front-door enterprise networks. All organizations running Citrix ADC or Gateway appliances are potentially affected, with internet-exposed devices at greatest risk. The flaw is being actively exploited in the wild, including by state-sponsored actors; it was added to CISA KEV on 2022-12-13 and Citrix and the NSA publicly urged admins to patch, though no public proof-of-concept is known. Do: Apply the fixed firmware updates per Citrix's vendor instructions immediately, prioritizing internet-facing ADC and Gateway appliances, since the flaw is in CISA KEV and actively exploited by state-sponsored actors. Until patched, restrict or shield appliance interfaces where feasible, and review internet-exposed devices for indicators of compromise given the absence of a public PoC. | 9.8 | 7% | KEV |
| largetens of thousands of internet-exposed ADC/Gateway appliances, with thousands reported still unpatched after disclosure | |
| CVE-2022-31702 | vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2022-31703 | The vRealize Log Insight contains a Directory Traversal Vulnerability. The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2022-31705 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. NVD description · AI analysis pending | 8.2 | 2% |
| — | ||
| CVE-2022-42475 | Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE) CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching. Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched. | 9.8 | 99% | KEV ransomware PoC |
| masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign) |
Full article484 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 14, 2022Application Security / Zero-Day
The U.S. National Security Agency (NSA) on Tuesday said a threat actor tracked as APT5 has been actively exploiting a zero-day flaw in Citrix Application Delivery Controller (ADC) and Gateway to take over affected systems.
The critical remote code execution vulnerability, identified as CVE-2022-27518, could allow an unauthenticated attacker to execute commands remotely on vulnerable devices and seize control.
Successful exploitation, however, requires that the Citrix ADC or Citrix Gateway appliance is configured as a SAML service provider (SP) or a SAML identity provider (IdP).
The following supported versions of Citrix ADC and Citrix Gateway are affected by the vulnerability -
- Citrix ADC and Citrix Gateway 13.0 before 13.0-58.32
- Citrix ADC and Citrix Gateway 12.1 before 12.1-65.25
- Citrix ADC 12.1-FIPS before 12.1-55.291
- Citrix ADC 12.1-NDcPP before 12.1-55.291
Citrix ADC and Citrix Gateway versions 13.1 are not impacted. The company also said there are no workarounds available "beyond disabling SAML authentication or upgrading to a current build."
The virtualization services provider said it's aware of a "small number of targeted attacks in the wild" using the flaw, urging customers to apply the latest patch to unmitigated systems.
APT5, also known as Bronze Fleetwood, Keyhole Panda, Manganese, and UNC2630, is believed to operate on behalf of Chinese interests. Last year, Mandiant revealed espionage activity targeting verticals that aligned with government priorities outlined in China's 14th Five-Year Plan.
Those attacks entailed the abuse of a then-disclosed flaw in Pulse Secure VPN devices (CVE-2021-22893, CVSS score: 10.0) to deploy malicious web shells and exfiltrate valuable information from enterprise networks.
"APT5 has demonstrated capabilities against Citrix Application Delivery Controller deployments," NSA said. "Targeting Citrix ADCs can facilitate illegitimate access to targeted organizations by bypassing normal authentication controls."
Microsoft, last month, pointed out Chinese threat actors' history of discovering and using zero days to their advantage before being picked up by other adversarial collectives in the wild.
News of the Citrix bug also comes a day after Fortinet revealed a severe vulnerability that also facilitates remote code execution in FortiOS SSL-VPN devices (CVE-2022-42475, CVSS score: 9.3).
VMWare releases updates for code execution vulnerabilities
In a related development, VMware disclosed details of two critical flaws impacting ESXi, Fusion, Workstation, and vRealize Network Insight (vRNI) that could result in command injection and code execution.
- CVE-2022-31702 (CVSS score: 9.8) - Command injection vulnerability in vRNI
- CVE-2022-31703 (CVSS score: 7.5) - Directory traversal vulnerability in vRNI
- CVE-2022-31705 (CVSS score: 5.9/9.3) - Heap out-of-bounds write vulnerability in EHCI controller
"On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed," the company said in a security bulletin for CVE-2022-31705.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/12/hackers-actively-exploiting-citrix-adc.html