HomeSecurityCitrix: fixes 11 flaws in its products

Citrix: fixes 11 flaws in its products

As it informed its customers, Citrix has patched 11 vulnerabilities in its ADC , Gateway , and SD-WAN networking products , emphasizing that these flaws are not related to CVE-2019-19781 , which has been exploited in many attacks .

Citrix

In fact, after the announcement of the flaws and the details about them, the company's CISO, Fermin J. Serna, posted a statement to "avoid confusion and limit the possibility of misinterpretation in the industry and all of our customers."

As Serna notes, the newly patched vulnerabilities are in no way related to CVE-2019-19781, which has been exploited by malicious actors multiple times since it was discovered in January. The vulnerability, which has been exploited by both government and profit-seeking hackers , has caused a series of serious problems for many organizations

Citrix had initially released interim measures for CVE-2019-19781, due to the high risk of exploitation, while regular patches took several weeks to be released. As for the new flaws the company identified in its products, they are fully fixed by the security updates it has released and, as it stated, it has not discovered any evidence that they have been exploited.   

Citrix: fixes 11 flaws in its products

The newly patched vulnerabilities affect Citrix ADC, Gateway, and the SD-WAN WAN Optimization (WANOP) edition and can be exploited to steal information, launch DoS attacks, local privilege escalation, XSS attacks, bypass authorization, and add malicious code.

Some of the flaws could be exploited remotely by an attacker, but most require system access or some kind of user interaction, while cloud versions of the products are not affected by them.

However, despite the small risk of exploiting these flaws, Citrix recommends that its customers update their systems immediately.

As Serna states, “We are limiting public disclosure of many of the technical details of vulnerabilities and fixes to further protect our customers. Across the industry, sophisticated malicious actors are using the details and patches to reverse the exploit. As such, we are taking steps to advise and assist our customers, but also to do everything we can to protect their discovery from malicious actors.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS