Citrix ADC and Gateway need urgent patches

By

NSA warns APT5 group already exploiting vulns.

The US National Security Agency is warning that the threat group known as APT5 is exploiting bugs in Citrix’s Application Delivery Controller product.

Citrix ADC and Gateway need urgent patches
File photo.

Citrix said in its blog post that the bug, CVE-2022-27518, also affects its Gateway product.

The bug affects versions 12.1 and 13.0 before 13.0-58.32 of the products, if they are “configured with an SAML SP or IdP configuration to be affected”. SAML is an authentication protocol; IdP stands for “identity provider”.

The company has provided updated software to fix the issue.

The NSA’s advisory [pdf] states that exploits “can facilitate illegitimate access to targeted organizations by bypassing normal authentication controls”.

It offered guidance on “steps organisations can take to look for possible artifacts of this type of activity”.

These include checking the integrity of executables in their Citrix environment by comparing MD5 hashes to known good binaries; checking logs for markers of APT5 activity; and using NSA-provided YARA signatures that can detect known APT5 malware.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Accenture to buy Australian cyber security firm CyberCX

Accenture to buy Australian cyber security firm CyberCX

Greater Western Water's billing system data issues laid bare

Greater Western Water's billing system data issues laid bare

TPG Telecom reveals iiNet order management system breached

TPG Telecom reveals iiNet order management system breached

Log In

  |  Forgot your password?