Tuesday, May 28, 2024

Critical Citrix ADC and Gateway Auth Bypass Flaw Let Attackers Gain Unauthorized Access

Citrix published security patches to fix a critical authentication bypass issue in Citrix ADC and Citrix Gateway. It is advised that impacted users of Citrix ADC and Citrix Gateway install the relevantly updated versions of those products as early as possible.

Citrix Gateway is a commonly used cloud-based or on-premises business server SSL VPN service that offers secure remote access with identity and access management capabilities.

For enterprise-deployed cloud applications, Citrix ADC is a load-balancing solution that guarantees continuous availability and the best performance.

“Note that only appliances that are operating as a Gateway (appliances using the SSL VPN functionality or deployed as an ICA proxy with authentication enabled) are affected by the first issue, which is rated as a Critical severity vulnerability”, reads the Citrix security bulletin.

Vulnerabilities Addressed

The company fixed three vulnerabilities overall. The three flaws can allow attackers to bypass login brute force protection, perform remote desktop takeover, or get unauthorized access to the device depending on the configuration.

Critical-severity authentication bypassing using an alternate path or channel is exploitable only if the appliance is configured as VPN (Gateway).

An insufficient verification of data authenticity allows remote desktop takeover via phishing. The issue is exploitable only if the appliance is configured as VPN (Gateway), and the RDP proxy functionality is configured.

It is a user login brute force protection functionality bypass. This vulnerability can only be exploited if the appliance is configured as VPN (Gateway) or AAA virtual server with a “Max Login Attempts” configuration.

The Following Versions of Citrix ADC and Citrix Gateway are Affected By This Vulnerability

  • Citrix ADC and Citrix Gateway 13.1 before 13.1-33.47 
  • Citrix ADC and Citrix Gateway 13.0 before 13.0-88.12 
  • Citrix ADC and Citrix Gateway 12.1 before 12.1.65.21
  • Citrix ADC 12.1-FIPS before 12.1-55.289 
  • Citrix ADC 12.1-NDcPP before 12.1-55.289

The company said this applies to customer-managed Citrix ADC and Citrix Gateway appliances. Customers using Citrix-managed cloud services do not need to take any action.

Notably, Citrix ADC and Citrix Gateway versions prior to 12.1 are EOL, and customers on those versions are recommended to upgrade to one of the supported versions.

Managed DDoS Attack Protection for Applications – Download Free Guide

Website

Latest articles

GNOME Remote Desktop Vulnerability Let Attackers Read Login Credentials

GNOME desktop manager was equipped with a new feature which allowed remote users to...

Kesakode: A Remote Hash Lookup Service To Identify Malware Samples

Today marks a significant milestone for Malcat users with the release of version 0.9.6,...

Cisco Firepower Vulnerability Let Attackers Launch SQL Injection Attacks

 A critical vulnerability has been identified in Cisco Firepower Management Center (FMC) Software's web-based...

Hackers Exploit WordPress Plugin to Steal Credit Card Data

Hackers have exploited an obscure WordPress plugin to inject malware into websites, specifically targeting...

Google Patches Chrome Zero-Day: Type Confusion in V8 JavaScript

Google has released a patch for a zero-day exploit in its Chrome browser.The...

Hackers Created Rogue VMs in Recent MITRE’s Cyber Attack

State-sponsored hackers recently exploited vulnerabilities in MITRE's Networked Experimentation, Research, and Virtualization Environment (NERVE).They...

Hackers Weaponizing Microsoft Access Documents To Execute Malicious Program

In multiple aggressive phishing attempts, the financially motivated organization UAC-0006 heavily targeted Ukraine, utilizing...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Live API Attack Simulation

94% of organizations experience security problems in production APIs, and one in five suffers a data breach. As a result, cyber-attacks on APIs increased from 35% in 2022 to 46% in 2023, and this trend continues to rise.
Key takeaways include:

  • An exploit of OWASP API Top 10 vulnerability
  • A brute force ATO (Account Takeover) attack on API
  • A DDoS attack on an API
  • Positive security model automation to prevent API attacks

Related Articles