CERT-In Vulnerability Note
CIVN-2022-0271
Multiple Vulnerabilities in Citrix Products
Original Issue Date:June 16, 2022
Severity Rating: HIGH
Software Affected
- Citrix ADM 13.1 before 13.1-21.53
- Citrix ADM 13.0 before 13.0-85.19
Overview
Multiple vulnerabilities have been reported in Citrix Application Delivery Management (ADM) Products which could allow a remote attacker to cause security bypass and denial of service condition on the targeted systems.
Description
1. Security Bypass Vulnerability
(
CVE-2022-27511
)
This vulnerability exists in Citrix ADM due to improper access control. A remote attacker could exploit this vulnerability by sending a specially-crafted request to corrupt the system and reset the administrator password at the next device reboot. Successful exploitation of this vulnerability could allow a remote attacker to bypass security and cause improper access control on an affected device.
2. Denial of Service Vulnerability
(
CVE-2022-27512
)
This vulnerability exists in Citrix ADM due to a use-after-free flaw in the ADM license service. A remote attacker could exploit this vulnerability by sending a specially-crafted request to prevent new licenses from being issued or renewed, and results in a denial-of-service condition. Successful exploitation of this vulnerability could allow a remote attacker to cause denial of service condition on the targeted system.
Solution
Apply appropriate upgrade as mentioned:
https://support.citrix.com/article/CTX460016
Vendor Information
Citrix
https://support.citrix.com/article/CTX460016
References
Citrix
https://support.citrix.com/article/CTX460016
CVE Name
CVE-2022-27511
CVE-2022-27512
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|