PT-2022-6073 · Citrix · Citrix Gateway+1

Published

2022-11-08

·

Updated

2023-10-18

·

CVE-2022-27513

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix ADC (formerly Citrix NetScaler Application Delivery Controller) versions (affected versions not specified) Citrix Gateway (formerly Citrix NetScaler Gateway) versions (affected versions not specified)
Description The issue is related to insufficient authentication data validation in the Citrix ADC and Citrix Gateway systems. This can allow a remote attacker to gain access to the gateway when it is configured in RDP proxy mode. The vulnerability can be exploited via remote desktop takeover using phishing.
Recommendations For Citrix ADC, consider restricting access to the RDP proxy mode until a fix is available. For Citrix Gateway, restrict access to the gateway when it is configured in RDP proxy mode to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00008
CVE-2022-27513

Affected Products

Citrix Adc
Citrix Gateway