Citrix Application Delivery Management (ADM) is an intuitive, comprehensive platform that enables automation, orchestration, management, and analytics for application delivery across hybrid multi-cloud environments. Citrix ADM offers a web-based technology for handling Citrix deployment in the cloud or on-premise. Citrix is known for thin client computing and it offers a range of networking products that improves the delivery speed and quality of apps served to users. This utility is provided through load balancing and web app acceleration technologies.
Citrix has released security updates to address vulnerabilities in ADM. A threat actor could exploit these vulnerabilities to take control of an affected system.
CVE-2022-27511: Allows remote, unauthenticated threat actors to not only crash a system via a denial-of-service (DoS) exploit and could reset admin credentials on the next subsequent reboot.
CVE-2022-27512: Allows temporarily disrupting the ADM license service.
CISA encourages users and administrators to review Citrix Security Update CTX460016 and apply the necessary updates. If these vulnerabilities get exploited, could result in the following security issues:
- Corruption of the system by a remote, unauthenticated threat actor. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the appliance has rebooted.
- Temporary interruption of the ADM license service. The impact of this includes preventing new licenses from being released or renewed by Citrix ADM.
All versions of Citrix ADM server and Citrix ADM agent are affected by this vulnerability.
The affected versions are:
- Citrix ADM 13.1 before 13.1-21.53
- Citrix ADM 13.0 before 13.0-85.19
Citrix ADM 12.1 is no longer supported and has now reached end of life. Users running Citrix ADM 12.1 should update to version 13.
These vulnerabilities have already been fixed in Citrix ADM service. Customers using Citrix ADM service do not need to take any action.
Mitigation
Cyber security experts recommend that network traffic to the Citrix ADM’s IP address is segmented, either physically or logically. Doing this reduces the probability of exploitation of these issues.
Citrix recommends that affected customers must upgrade both Citrix ADM server and all associated Citrix ADM agents
Citrix recommends that affected customers must upgrade both Citrix ADM server and all associated Citrix ADM agents
He is a cyber security and malware researcher. He studied Computer Science and started working as a cyber security analyst in 2006. He is actively working as an cyber security investigator. He also worked for different security companies. His everyday job includes researching about new cyber security incidents. Also he has deep level of knowledge in enterprise security implementation.