CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2022-27518

CVSS 9.8v3.1pub. 2022-12-13upd. 2026-02-25

Unauthenticated remote arbitrary code execution

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Citrix Application Delivery Controller

    HW
    Citrix
    all versions
  • Citrix Application Delivery Controller Firmware

    OS
    Citrix
    12.1 – 12.1-65.25 (excl.)13.0 – 13.0-58.32 (excl.)12.1 – 12.1-55.291 (excl.)
  • Citrix Gateway

    HW
    Citrix
    all versions
  • Citrix Gateway Firmware

    OS
    Citrix
    12.1 – 12.1-65.25 (excl.)13.0 – 13.0-58.32 (excl.)

CISA KEV — detailsi

Vendori
Citrix
Producti
Application Delivery Controller (ADC) and Gateway
Added to KEVi
December 13, 2022
Remediation deadline (US Federal)i
January 3, 2023(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 stycznia 2023
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2019-19781CRITICAL9.8⚠ KEVPL ✓same product

Path Traversal w Citrix ADC i Gateway umożliwiający RCE

CVE-2022-27510CRITICAL9.8PL ✓same product

Citrix Gateway / ADC — nieautoryzowany dostęp do funkcji użytkownika Gateway

CVE-2019-18225CRITICAL9.8PL ✓same product

Citrix ADC i Gateway — obejście uwierzytelnienia przez interfejs zarządzania

CVE-2018-7218CRITICAL9.8PL ✓same product

RCE w funkcji AppFirewall Citrix NetScaler ADC i NetScaler Gateway

CVE-2022-27508HIGH7.5same product

Unauthenticated denial of service