Thousands of Citrix ADC and Gateway servers are still exposed to two critical security vulnerabilities, even though the vendor has taken steps to patch them in recent months.
See also: Citrix patches critical zero-day in ADC and Gateway

The original vulnerability, designated CVE-2022-27510 , was patched on November 8. It identified an authentication flaw that applies to both Citrix products. A malicious actor could exploit this vulnerability to gain unauthorized access, perform a remote desktop takeover attack , or even bypass brute force protections .
On December 13, a security vulnerability known as CVE-2022-27518, and was patched shortly thereafter. By exploiting vulnerable devices, unauthorized attackers can execute commands remotely and gain unauthorized access to them.
Even before Citrix released a patch to fix CVE-2022-27518, malicious actors had already begun exploiting the security vulnerability.
According to a recent report by NCC Group 's Fox IT team , while most publicly accessible Citrix endpoints have been upgraded to secure versions, unfortunately thousands are still at risk .
On November 11, 2022, Fox IT analysts conducted an extensive scan of the internet and identified 28,000 Citrix servers that were up and running.
To assess which of the exposed systems are vulnerable to both vulnerabilities, the researchers had to uncover the version number – information that is absent from the servers' HTTP response.
However, the responses contained MD5 hash that could be cross-referenced with the versions of the Citrix ADC and Gateway products.
As a result, the team searched Citrix, Google Cloud Marketplace, AWS, and Azure for all available versions of Citrix ADC before downloading them to virtual machines to verify that their hashes were up to date.
See also: Citrix to admins: Fix critical vulnerabilities in Gateway and ADC

With the hashes unable to be linked to the downloaded versions, researchers resorted to deciphering the build date and then determining the version number based on it.
This move further reduced the number of unknown versions, however most of the fragmentations were still associated with separate product versions.
The second most popular version, 12.1-65.21, was installed on 3,500 endpoints and could be affected by CVE-2022-27518 under certain conditions.
For these machines to be vulnerable, SAML SP or IdP configurations must be used. Therefore, not all 3,500 systems were vulnerable to CVE-2022-27518.
Additionally, there are more than 1,000 servers exposed to CVE-2022-27510 and approximately 3,000 endpoints that could be vulnerable to both critical vulnerabilities.
The United States, Germany, Canada, Australia and Switzerland acted swiftly after the safety alerts were released.
With recent security threats, Fox IT aims to raise awareness among Citrix administrators who have yet to apply critical updates. The statistics reveal that there is a lot of work to be done in order to protect against further breaches and close these gaps quickly and effectively.
See also: Citrix confirms DDoS attack affecting NetScaler ADCs
Citrix is a software company focused on cloud computing, networking, and virtualization. It has been around since 1989 and provides a range of products and services designed to help businesses manage their IT operations more effectively. With a wide range of products and services, it can offer you everything you need to maximize efficiency within your organization while keeping costs down.
