ZeroHour
Security Affairspublished ()ingested @securityaffairs

Thousands of Citrix servers still vulnerable to CVE-2022-27510 and CVE-2022

criticalVulnerability exploited in the wildimportance 60CVE-2022-27510CVE-2022-27518

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27510
Unauthorized access to Gateway user capabilities

Unauthorized access to Gateway user capabilities

NVD description · AI analysis pending
9.81%
  • citrix gateway
  • citrix application delivery controller firmware
CVE-2022-27518
Unauthenticated RCE/Authentication Bypass in Citrix ADC and Gateway

CVE-2022-27518 is a critical flaw in Citrix Application Delivery Controller (ADC) and Gateway firmware that permits unauthenticated remote arbitrary code execution, which CISA characterizes as an authentication bypass. It is triggered remotely over the network with no credentials, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N, score 9.8), so any affected appliance with an internet-reachable interface is a potential target. A successful attacker gains code execution on the appliance and access to sensitive resources, which is especially dangerous on VPN gateway and load-balancing deployments that front-door enterprise networks. All organizations running Citrix ADC or Gateway appliances are potentially affected, with internet-exposed devices at greatest risk. The flaw is being actively exploited in the wild, including by state-sponsored actors; it was added to CISA KEV on 2022-12-13 and Citrix and the NSA publicly urged admins to patch, though no public proof-of-concept is known.

Do: Apply the fixed firmware updates per Citrix's vendor instructions immediately, prioritizing internet-facing ADC and Gateway appliances, since the flaw is in CISA KEV and actively exploited by state-sponsored actors. Until patched, restrict or shield appliance interfaces where feasible, and review internet-exposed devices for indicators of compromise given the absence of a public PoC.

9.87% KEV
  • Citrix Application Delivery Controller (ADC) firmware
  • Citrix Gateway firmware
largetens of thousands of internet-exposed ADC/Gateway appliances, with thousands reported still unpatched after disclosure
Full article586 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 29, 2022

Researchers warn of thousands of Citrix Application Delivery Controller (ADC) and Gateway endpoints are still unpatched.

NCC Group’s Fox-IT research team warns of thousands of Citrix ADC and Gateway endpoints remain vulnerable to two critical vulnerabilities, tracked as CVE-2022-27510 and CVE-2022-27518 (CVSS scores: 9.8), that the company addressed in recent months.

CVE-2022-27510 flaw is an authentication bypass using an alternate path or channel. An attacker can trigger it to gain unauthorized access to Gateway user capabilities. The vendor pointed out that only appliances that are operating as a Gateway (appliances using the SSL VPN functionality or deployed as an ICA proxy with authentication enabled) are impacted. 

Citrix addressed the flaw on November 8, 2022.

The CVE-2022-27518 flaw is a remote code execution bug that can be exploited by an unauthenticated, remote attacker to gain arbitrary code execution on the vulnerable appliance. 

On December 13, the vendor urged administrators to apply security updates for the zero-day vulnerability in ADC and Gateway that was actively exploited by China-linked threat actors to gain access to target networks.

Now researchers at NCC Group’s Fox IT team reported despite most internet-facing endpoints have been updated to versions that fix both issues, thousands of installs remain vulnerable.

The researchers initially scanned the Internet for Citrix servers and found around 28.000 installs as of November 11, 2022.

Unfortunately, the version number of these installs was not included in the HTTP response from the servers. The experts noticed that there is an MD5 hash-like value in the HTTP body when requesting the URL:

/vpn/index.html 

Then they downloaded and deployed all Citrix ADC versions from cloud marketplaces, including Google Cloud Marketplace, AWS, Azure, and Citrix, and analyzed the matches between hashes and versions.

The research team noticed that some hashes could not be matched with the versions obtained with the described process, then analyzed the build date to deduce their versions.

The following graph shows the Top 20 active versions on the internet as of December 28, 2022, and reports if those versions are vulnerable to both issues:

The good news is that the majority of the servers, more than 5,000, are running the 13.0-88.14 version that’s not impacted by the two flaws.

Over 3,500 Citrix ADC and Gateway servers are running the 12.1-65.21 version which is vulnerable to CVE-2022-27518 attacks, while more than 500 servers are running the 12.1-63.22 version which is vulnerable to both critical flaws.

This second graph shows the Top 20 countries using Citrix ADC / Gateway and how many of them are still vulnerable.

In China, only 20% of internet-facing servers have been updated against both issues.

“In this blog, we’ve shown how we performed the version identification of Citrix ADC and Citrix Gateway servers by analysing disk images exported from Google Cloud Marketplace using dissect. We also demonstrated that gzip files can be helpful for timestamp information and how we utilised this to find and download missing Citrix ADC builds.” concludes the report. “Finally, we used the version identification data to measure the versions of internet-facing Citrix ADC and Gateway servers over time and see that the NSA and Citrix advisory really helped with updates. However, some servers remain vulnerable to CVE-2022-27510 or CVE-2022-27518. We hope this blog creates extra awareness for these two Citrix CVEs and that our research on version identification contributes to future studies.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Citrix)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/140112/hacking/citrix-servers-vulnerable-online.html