{"id":13186,"date":"2022-11-10T00:42:39","date_gmt":"2022-11-09T23:42:39","guid":{"rendered":"http:\/\/nfirjun2026.local\/nfir-threat-intelligence-report-on-critical-vulnerability-in-citrix\/"},"modified":"2024-02-12T14:18:48","modified_gmt":"2024-02-12T13:18:48","slug":"nfir-threat-intelligence-report-on-critical-vulnerability-in-citrix","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/nfir-threat-intelligence-report-on-critical-vulnerability-in-citrix\/","title":{"rendered":"NFIR Threat Intelligence Report on critical vulnerability in Citrix"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"13186\" class=\"elementor elementor-13186 elementor-11694\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06c4724 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06c4724\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fb77167\" data-id=\"fb77167\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-27be329 elementor-widget elementor-widget-heading\" data-id=\"27be329\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What are Citrix ADC \/ Gateway?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-cca9d26 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cca9d26\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b11f1dc\" data-id=\"b11f1dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1234310 elementor-widget elementor-widget-text-editor\" data-id=\"1234310\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Citrix Applicaton Delivery Controller, or ADC (formerly NetScaler ADC) is a solution for application delivery and load balancing. It is used to facilitate applications within enterprise environments. Citrix Gateway is an on-premise solution that facilitates remote access and provides access to apps and resources.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-710ae6a elementor-widget elementor-widget-heading\" data-id=\"710ae6a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What potential impact does this vulnerability have?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-05001af elementor-widget elementor-widget-text-editor\" data-id=\"05001af\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If an attacker is able to successfully exploit the vulnerability, it could lead to unauthorized access to Citrix systems, as well as underlying systems that are part of the network infrastructure.<\/p>\n<p>To exploit this vulnerability, the system must be set up as a gateway using the SSL VPN functionality or if the system is configured as an ICA proxy with authentication. Citrix scales the vulnerability as &#8220;critical.&#8221;<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-029f215 elementor-widget elementor-widget-heading\" data-id=\"029f215\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What are the recommendations?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e26af1c elementor-widget elementor-widget-text-editor\" data-id=\"e26af1c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NFIR advises affected Citrix ADC and Citrix Gateway customers to install the relevant updated versions of Citrix ADC or Citrix Gateway as soon as possible:<\/p>\n<ul>\n<li>Citrix ADC and Citrix Gateway 13.1-33.47 and later versions<\/li>\n<li>Citrix ADC and Citrix Gateway 13.0-88.12 and later versions of 13.0<\/li>\n<li>Citrix ADC and Citrix Gateway 12.1-65.21 and later versions of 12.1<\/li>\n<li>Citrix ADC 12.1-FIPS 12.1-55.289 and later versions of 12.1-FIPS<\/li>\n<li>Citrix ADC 12.1-NDcPP 12.1-55.289 and later versions of 12.1-NDcPP<\/li>\n<\/ul>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-07e0507 elementor-widget elementor-widget-heading\" data-id=\"07e0507\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Is there a plan of action?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-f4bff09\" data-id=\"f4bff09\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-996aa7a elementor-widget elementor-widget-image\" data-id=\"996aa7a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"2560\" height=\"1029\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo.png\" class=\"attachment-full size-full wp-image-11697\" alt=\"NFIR Threat Intelligence Report on critical vulnerability in Citrix\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo.png 2560w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo-300x121.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo-1024x412.png 1024w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo-768x309.png 768w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo-1536x617.png 1536w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo-2048x823.png 2048w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49b2fd5 elementor-widget elementor-widget-button\" data-id=\"49b2fd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/NFIR-Threat-Intelligence-Report-Kritieke-kwetsbaarheden-in-Citrix-v1.0-1.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Threat Intelligence Report on vulnerability in Confluence (CVE-2022-26134) here.<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<div class=\"elementor-element elementor-element-6817752 elementor-widget elementor-widget-text-editor\" data-id=\"6817752\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>It is important for your organization to take at least the following steps:<\/p>\n<ol>\n<li>Check (if available) publicly available Indicators-of-Compromise (IoCs) on your systems to determine if any systems may have been compromised, or have external preventive research performed on your systems.<\/li>\n<li>Prepare your organization for the situation when patches need to be executed unexpectedly (outside the regular update timeframes) and apply patches in a controlled manner according to the procedure usual for your organization.<\/li>\n<li>Immediately run the available security updates\/patches as soon as they are published on the systems and verify that the updates have actually been applied. In case you have an external IT service provider: Have your provider perform these actions and have them confirm the actions and their result to you in writing.<\/li>\n<\/ol>\n<p>Do you have systems where the risk is high (for example, systems with sensitive or special personal data)? Then consider temporarily disabling the system.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c46633f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c46633f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-135a0ec\" data-id=\"135a0ec\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6954542 elementor-widget elementor-widget-text-editor\" data-id=\"6954542\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Disclaimer: NFIR has made every effort to make this information accurate and reliable. However, the information provided is without any guarantee of any kind and its use is entirely at the risk of the user. NFIR assumes no responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided.<\/em><\/p><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e932ea2 elementor-widget elementor-widget-button\" data-id=\"e932ea2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/NFIR-Threat-Intelligence-Report-Kritieke-kwetsbaarheden-in-Citrix-v1.0-1.pdf\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Threat Intelligence Report on vulnerability in Confluence (CVE-2022-26134) here.<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Citrix Applicaton Delivery Controller, or ADC (formerly NetScaler ADC) is a solution for application delivery and load balancing. It is used to facilitate applications within enterprise environments. Citrix Gateway is an on-premise solution that facilitates remote access and provides access to apps and resources.<\/p>\n","protected":false},"author":4,"featured_media":16707,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"","_seopress_titles_desc":"Citrix Applicaton Delivery Controller, or ADC (formerly NetScaler ADC) is a solution for application delivery and load balancing. It is used to facilitate applications within enterprise environments. Citrix Gateway is an on-premise solution that facilitates remote access and provides access to apps and resources.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"40","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo.png","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/11\/Citrixlogo.png","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29,51],"tags":[],"class_list":["post-13186","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en","category-threat-intelligence-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/13186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=13186"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/13186\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/16707"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=13186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=13186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=13186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}