QID 150583

QID 150583: Citrix Application Delivery Management (ADM) Multiple Vulnerablities (CVE-2022-27511, CVE-2022-27512)

Citrix Application Delivery Management (ADM) is a centralized management solution. It simplifies operations by providing administrators with enterprise-wide visibility and automating management jobs that are getting ran across multiple instances.

CVE-2022-27511 allows corruption of the system by a remote, unauthenticated user potentially leading to the reset of the administrator password.

CVE-2022-27512 allows Temporary disruption of the ADM license service.

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to corrupt the system remotely. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted along with Temporary disruption of the ADM license service, thereby preventing new licenses from being issued or renewed by Citrix ADM.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade to latest Citrix ADM solutions. For more information regarding this vulnerability please refer Citrix Security Advisory https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512.

    CVEs related to QID 150583

    Software Advisories
    Advisory ID Software Component Link
    Citrix Security Advisory URL Logo support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512