HomeSecurityCitrix: Patches released for critical vulnerability!

Citrix: Patches released for critical vulnerability!

Citrix has released patches to address a vulnerability in its ADC tool. The vulnerability, reported as CVE-2019-19781, affects Citrix Software Supply Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP.

“The scope of this vulnerability includes Citrix ADC and Citrix Gateway Digital Home Equipment (VPX) hosted on any Citrix Hypervisor, ESX, Hyper-V, KVM, Azure, AWS, GCP, or a Citrix ADC Provider Equipment Supply (SDX),” the company says.

The vulnerability can also be used to unleash arbitrary code without the authentication.

At the time of its disclosure, the security flaw had not been patched and about 80,000 organizations in 159 countries were at risk, said Mikhail Klyuchnikov, who initially reported the problem.

patches

Citrix also released some advice until the patch is released.

Citrix ADC and Citrix Gateway model 13.zero, Citrix ADC and NetScaler Gateway model 12.1, Citrix ADC and NetScaler Gateway model 12.zero, Citrix ADC and NetScaler Gateway model 11.1, and Citrix NetScaler ADC and NetScaler Gateway 10.five, and all supported builds are affected, along with SD-WAN WANOP product variants 10.2.6 and 11.zero.three.

It is worth noting that since GitHub made the exploit code public, attacks have become commonplace.

According to FireEye, a hacker working on a Tor infrastructure has developed an additional payload for growing attacks referred to as NotRobin.

This immediately prompted Citrix to release a schedule of expected fixes, with patches for versions 13 and 12.1 on January 27, on January 31 for version 10.five, and on January 20 for versions 12 and 11.1.

The fixes for ADC versions 12 and 11.1 were released today. The safety advisory states that users should “set up” the patches immediately, noting that if multiple ADC variants are used, IT admins should check the fixes that have been released for various builds.

“These fixes are also observed on Citrix ADC and Citrix Gateway Digital Home Appliance (VPX) hosted on any of ESX, Hyper-V, KVM, XenServer, Azure, AWS, GCP, or Citrix ADC Provider Equipment Supply (SDX). The SVM on the SDX does not need to be updated,” Citrix said. “It is important to update all Citrix ADC and Citrix Gateway 11.1 (MPX or VPX) instances to build 11.1.63.15 to apply the security fixes. As well as Citrix ADC and Citrix Gateway 12.zero (MPX or VPX) instances to build 12.zero.63.13 to apply the security.”

Additionally, Citrix has reduced the wait time for the worm to be patched across versions. Citrix ADC patches for models 12.1, 13, and 10.five are now expected on January 24th, and a Citrix SD-WAN WANOP patch could also be released on the same day.

Citrix has provided another verification for IT admins to check that the fixes were made correctly.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS