Executive brief
Citrix ADC and Gateway, when configured as a SAML Service Provider or Identity Provider, contain an authentication bypass vulnerability. An unauthenticated remote attacker can exploit this to achieve arbitrary code execution with administrator privileges.
Affected products
- Citrix Application Delivery Controller (ADC) Firmware 12.1 (including) up to 12.1-65.25 (excluding); 13.0 (including) up to 13.0-58.32 (excluding)
- Citrix Gateway Firmware 12.1 (including) up to 12.1-65.25 (excluding); 13.0 (including) up to 13.0-58.32 (excluding)
Timeline
- 2022-12-13: disclosed
- 2022-12-13: advisory: Vendor advisory CTX474995 published
- 2022-12-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-12-13: exploited: Reported as exploited in the wild at time of disclosure