Citrix ADC and Gateway need urgent patches

By

NSA warns APT5 group already exploiting vulns.

The US National Security Agency is warning that the threat group known as APT5 is exploiting bugs in Citrix’s Application Delivery Controller product.

Citrix ADC and Gateway need urgent patches
File photo.

Citrix said in its blog post that the bug, CVE-2022-27518, also affects its Gateway product.

The bug affects versions 12.1 and 13.0 before 13.0-58.32 of the products, if they are “configured with an SAML SP or IdP configuration to be affected”. SAML is an authentication protocol; IdP stands for “identity provider”.

The company has provided updated software to fix the issue.

The NSA’s advisory [pdf] states that exploits “can facilitate illegitimate access to targeted organizations by bypassing normal authentication controls”.

It offered guidance on “steps organisations can take to look for possible artifacts of this type of activity”.

These include checking the integrity of executables in their Citrix environment by comparing MD5 hashes to known good binaries; checking logs for markers of APT5 activity; and using NSA-provided YARA signatures that can detect known APT5 malware.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA using facial recognition logins to verify disputed payments

CBA using facial recognition logins to verify disputed payments

Qantas contacted by "potential cyber criminal"

Qantas contacted by "potential cyber criminal"

SA Power Networks tackles IAM, cloud security under five-year strategy

SA Power Networks tackles IAM, cloud security under five-year strategy

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Log In

  |  Forgot your password?