Citrix Alert
3097Warning Date
Severity Level
Warning Number
Target Sector
9 November, 2022
● Critical
2022-5349
All
Citrix has released a security updates to address a vulnerability in the following versions of Citrix Gateway and Citrix ADC:
- Citrix ADC and Citrix Gateway 13.1 before 13.1-33.47
- Citrix ADC and Citrix Gateway 13.0 before 13.0-88.12
- Citrix ADC and Citrix Gateway 12.1 before 12.1.65.21
- Citrix ADC 12.1-FIPS before 12.1-55.289
- Citrix ADC 12.1-NDcPP before 12.1-55.289
Remote attacker could exploit this vulnerability to bypass authentication and acquire access by using an alternate path or channel.
*The vulnerability requires that the Appliance must be configured as a (VPN Gateway)
The CERT team encourages users to review Citrix security advisory and apply the necessary updates: