PT-2022-6073 · Citrix · Citrix Gateway+1
Published
2022-11-08
·
Updated
2023-10-18
·
CVE-2022-27513
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Citrix ADC (formerly Citrix NetScaler Application Delivery Controller) versions (affected versions not specified)
Citrix Gateway (formerly Citrix NetScaler Gateway) versions (affected versions not specified)
Description
The issue is related to insufficient authentication data validation in the Citrix ADC and Citrix Gateway systems. This can allow a remote attacker to gain access to the gateway when it is configured in RDP proxy mode. The vulnerability can be exploited via remote desktop takeover using phishing.
Recommendations
For Citrix ADC, consider restricting access to the RDP proxy mode until a fix is available.
For Citrix Gateway, restrict access to the gateway when it is configured in RDP proxy mode to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Adc
Citrix Gateway