Site icon TheCyberThrone

Citrix NetScaler ADC Zeroday Flaw

Advertisements

Citrix has urged its customers to patch NetScaler ADC and Gateway products after discovering a critical-severity zero-day vulnerability.

The flaw tracked as CVE-2023-3519, with a CVSS score of 9.8, is an unauthenticated remote code execution and was observed exploited in the wild.

The vulnerability known to impact the following versions of the NetScaler ADC and Gateway products:

In order to exploit, the appliance must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Advertisements

Apart from the zero-day, other two more vulnerability impacting Citrix products are patched:

Companies should update the aforementioned versions to:

Although NetScaler ADC and NetScaler Gateway version 12.1 are also on the list of affected products, they were not patched. Both have reached the end-of-life stage, consequently, customers are advised to upgrade to a more recent version.

Exit mobile version