QID 730712
Date Published: 2023-01-31
QID 730712: Citrix Application Delivery Controller (ADC) and Citrix Gateway Arbitrary Code Execution Vulnerability (CTX474995)
A vulnerability has been discovered in Citrix Gateway and Citrix ADC, listed below, that, if exploited, could allow an unauthenticated remote attacker to perform arbitrary code execution on the appliance.
Affected Versions:
Citrix ADC and Citrix Gateway 13.0 before 13.0-58.32
Citrix ADC and Citrix Gateway 12.1 before 12.1-65.25
NOTE:
Citrix ADC or Citrix Gateway are only affected when either configured as a SAML SP or as a SAML IdP.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Citrix ADC/Netscaler by checking the version hash. The hash based check is added on the basis of the following Citrix Hashes. Please note that we can only detect vulnerable citrix versions that have an existing md5 hash in the provided list.
Successful exploitation allows attackers to execute arbitrary code.
Customers are advised to refer to CTX474995 for information pertaining to remediating this vulnerability.
- CTX474995 -
support.citrix.com/article/CTX474995
CVEs related to QID 730712
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CTX474995 |
|