Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Citrix Patches 11 Vulnerabilities in Networking Products

Citrix informed customers on Tuesday that it has patched 11 vulnerabilities in its ADC, Gateway, and SD-WAN networking products, and highlighted that the flaws are not related to CVE-2019-19781, which has been exploited in many attacks.

Citrix informed customers on Tuesday that it has patched 11 vulnerabilities in its ADC, Gateway, and SD-WAN networking products, and highlighted that the flaws are not related to CVE-2019-19781, which has been exploited in many attacks.

After publishing a security advisory describing the vulnerabilities, Citrix also published a blog post written by its CISO, Fermin J. Serna, in an effort to “avoid confusion and limit the potential for misinterpretation in the industry and our customer set.”

Serna pointed out that these newly patched vulnerabilities are not related to CVE-2019-19781, which hackers started exploiting in January, shortly after the flaw was disclosed. That security hole was exploited by both profit-driven cybercriminals and state-sponsored threat actors, and it caused a lot of problems for many organizations.

For CVE-2019-19781, Citrix initially released temporary mitigations due to the high risk of exploitation and released permanent patches only weeks later. In the case of the latest vulnerabilities, the company noted that they are fully addressed by the patches and it has found no evidence of malicious exploitation. The likelihood of exploitation is also considered lower.

The newly patched vulnerabilities affect Citrix ADC, Gateway, and the SD-WAN WAN Optimization (WANOP) edition, and they can be exploited for obtaining information, launching DoS attacks, local privilege escalation, XSS attacks, authorization bypass, and code injection.

While some of the flaws can be exploited by a remote and unauthenticated attacker, exploitation in most cases requires access to the targeted system, user interaction, or other preconditions. Moreover, cloud versions of the impacted products are not vulnerable to attacks.

Advertisement. Scroll to continue reading.

Despite the reduced risk of attacks exploiting these flaws, Citrix has advised customers to implement its security recommendations and install the patches as soon as possible.

“We are limiting the public disclosure of many of the technical details of the vulnerabilities and the patches to further protect our customers. Across the industry, today’s sophisticated malicious actors are using the details and patches to reverse engineer exploits. As such, we are taking steps to advise and help our customers but also do what we can to shield intelligence from malicious actors,” Serna said.

Related: Attacks on ADC Ramp Up as Citrix Releases Remaining Patches

Related: Organizations Quick to Patch Critical Citrix ADC Vulnerability

Related: Citrix Releases More Patches for Exploited Flaw, Tool to Detect Compromise

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.