Junglewise Threat Intelligence

CVE-2022-27518: Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

CVE-2022-27518 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-12-13

Technologies: Citrix NetScaler Gateway, Citrix Application Delivery Controller (ADC). Vendors: Citrix.

Executive brief

Citrix ADC and Gateway, when configured as a SAML Service Provider or Identity Provider, contain an authentication bypass vulnerability. An unauthenticated remote attacker can exploit this to achieve arbitrary code execution with administrator privileges.

Affected products

  • Citrix Application Delivery Controller (ADC) Firmware 12.1 (including) up to 12.1-65.25 (excluding); 13.0 (including) up to 13.0-58.32 (excluding)
  • Citrix Gateway Firmware 12.1 (including) up to 12.1-65.25 (excluding); 13.0 (including) up to 13.0-58.32 (excluding)

Timeline

  • 2022-12-13: disclosed
  • 2022-12-13: advisory: Vendor advisory CTX474995 published
  • 2022-12-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-12-13: exploited: Reported as exploited in the wild at time of disclosure

Related threats