QID 730802

Date Published: 2023-05-23

QID 730802: Citrix Application Delivery Controller (ADC) and Citrix Gateway Multiple Vulnerabilities (CTX477714)

Vulnerabilities have been discovered in Citrix Gateway and Citrix ADC.

CVE-2023-24488:- Cross site scripting Appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2023-24487:- Arbitrary file read Access to NSIP or SNIP with management interface access

Affected Versions:
Citrix ADC and Citrix Gateway 13.1 before 13.1-45.61
Citrix ADC and Citrix Gateway 13.0 before 13.0-90.11
Citrix ADC and Citrix Gateway 12.1 before 12.1-65.35

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Citrix ADC/Netscaler by checking the version hash. The hash based check is added on the basis of the following Citrix Hashes. Please note that we can only detect vulnerable citrix versions that have an existing md5 hash in the provided list.

Successful exploitation of this vulnerability may allow an attacker to either crash or service unavailability of the application.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Customers are advised to refer to CTX477714 for information pertaining to remediating this vulnerability.

    CVEs related to QID 730802

    Software Advisories
    Advisory ID Software Component Link
    CTX477714 URL Logo support.citrix.com/article/CTX477714/citrix-adc-and-citrix-gateway-security-bulletin-for-cve202324487-cve202324488