News: 1671001033

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Citrix patches critical ADC flaw the NSA says is already under attack from China

(2022/12/14)


The China-linked crime gang APT5 is already attacking a flaw in Citrix's Application Delivery Controller (ADC) and Gateway products that the vendor patched today.

Citrix says the flaw, CVE-2022-27518, "could allow an unauthenticated remote attacker to perform arbitrary code execution on the appliance" if it is configured as a SAML service provider or identity provider (SAML SP, SAML IdP).

Unusually, Citrix has a policy of not revealing the Common Vulnerability Scoring System (CVSS) scores for its flaws. CVSS rates flaws on a ten point scale, with anything rated above 9.0 deemed Critical and therefore worthy of urgent attention due to the significant risk of exploitation.

[1]

The Register suggests the flaw may be closer to a 10.0 score than a 9.0 rating, because [2]Citrix's announcement of the flaw was quickly followed by publication of a [3]threat hunting guidance [PDF] from the United States' National Security Agency (NSA), which believes a China-linked crime gang known as APT5 (aka UNC2630 and MANGANESE) has already "demonstrated capabilities" to attack Citrix ADCs.

[4]

[5]

The NSA's threat hunting guidance offers a detailed and lengthy procedure to detect a compromised ADC and warns that if one of the steps doesn't find evidence of an attack, others may.

"Treat these detection mechanisms as independent ways of identifying potentially malicious activity on impacted systems," the guidance states. "Artefacts may vary based on the environment and the stage of that activity. As such, NSA recommends investigating any positive result even if other detections return no findings."

[6]How Citrix dropped the ball on Xen ... according to Citrix

[7]Regulators approve Citrix/Tibco merger

[8]Microsoft extends Teams into VMware and Citrix VDI

[9]Citrix adds Hypervisor Cloud to bring more and faster updates

Citrix's [10]advice is to enable audit logging and apply the patches it has prepared for its products.

Security vendor Tenable has [11]analyzed the flaw and at the time of writing had not found proof-of-concept code for the flaw.

[12]

Citrix's ADCs are something of a favorite for Chinese attackers – four flaws in the product made the NSA's [13]25 most attacked flaws list in 2020.

One of the flaws on that list is the notorious [14]CVE-2019-19781 that allowed arbitrary code execution with no account credentials.

Citrix announced the flaw in late December 2019, but patches did not appear until [15]January 20 2020.

[16]

Citrix's [17]blog post and [18]support article about the new flaw don't include an apology or expression of regret. Long-suffering ADC customers might not accept one, anyway. ®

Get our [19]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y5ms08776Mq8H-xAkrN8uQAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/

[3] https://docs.google.com/viewer?url=https%3A%2F%2Fmedia.defense.gov%2F2022%2FDec%2F13%2F2003131586%2F-1%2F-1%2F0%2FCSA-APT5-CITRIXADC-V1.PDF

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5ms08776Mq8H-xAkrN8uQAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5ms08776Mq8H-xAkrN8uQAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/09/30/citrix_xen/

[7] https://www.theregister.com/2022/09/08/cirtix_tibco_delisting_merger_approved/

[8] https://www.theregister.com/2022/09/02/microsoft_teams_vmware_vdi/

[9] https://www.theregister.com/2022/08/05/citrix_hypervisor_cloud/

[10] https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/

[11] https://www.tenable.com/blog/cve-2022-27518-unauthenticated-rce-in-citrix-adc-and-gateway

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5ms08776Mq8H-xAkrN8uQAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2020/10/20/nsa_china_hacking/

[14] https://www.theregister.com/2020/01/13/security_roundup_100120/

[15] https://www.theregister.com/2020/01/20/citrix_patches_vulns_gateway_adc/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5ms08776Mq8H-xAkrN8uQAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/

[18] https://support.citrix.com/article/CTX474995/citrix-adc-and-citrix-gateway-security-bulletin-for-cve202227518

[19] https://whitepapers.theregister.com/



You are a taxi driver. Your cab is yellow and black, and has been in
use for only seven years. One of its windshield wipers is broken, and
the carburetor needs adjusting. The tank holds 20 gallons, but at the
moment is only three-quarters full. How old is the taxi driver?"