QID 150626
Date Published: 2022-12-26
QID 150626: Citrix Application Delivery Controller (ADC) and Citrix Gateway Remote Code Execution (RCE) Vulnerability (CVE-2022-27518)
A critical unauthenticated remote code execution (RCE) vulnerability has been discovered in Citrix Gateway and Citrix ADC.
Affected Versions:
Citrix ADC and Citrix Gateway 13.0 before 13.0-58.32
Citrix ADC and Citrix Gateway 12.1 before 12.1-65.25
NOTE:
According to Citrix Security Bulletin - CTX474995, Citrix ADC or Citrix Gateway are only affected by this vulnerability when configured as a SAML SP or as a SAML IdP.
QID Detection Logic (Basic Authentication) :
This QID sends an authenticated HTTP GET request to "/nitro/v1/config/nsversion" endpoint and checks for vulnerable versions of Citrix ADC/Netscaler.
Successful exploitation could allow an unauthenticated remote attacker to perform arbitrary code execution on the appliance.
Customers are advised to refer Citrix Security Bulletin - CTX474995 for information pertaining to remediating this vulnerability.
CVEs related to QID 150626
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CTX474995 |
|