Citrix rolled out some fixes to close nasty vulnerabilities in certain versions of its Application Delivery Controller (ADC) and Gateway products that could impact more than 25,000 servers. However, fixes for its SD-WAN and other ADC iterations are not expected until the end of the week.
The initial updates were launched on Sunday and are targeted at Citrix’s ADC 11.1 and 12.0 versions. They also apply to Citrix ADC and Gateway Virtual Appliances (VPX) hosted on VMware’s ESX, Microsoft’s Hyper-V, Linux KVM, Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), or on Citrix’s XenServer or ADC Service Delivery Appliance (SDX).
“We urge customers to immediately install these fixes,” Citrix’s Chief Information Security Officer (CISO) Fermin Serna noted in a blog post.
Serna added that the second round of permanent updates are set to be released on Friday. Those will re-secure ADC and Gateway versions 10.5, 12.1, and 13.0, and Citrix’s SD-WAN WAN Optimization (WANOP) platform. Citrix had initially stated a month-end deadline for rolling out the full slate of updates.
Wild BugsThe vulnerabilities, which are grouped under the CVE-2019-19781 name, were initially discovered in December. They can allow an attacker to access private enterprise networks without authentication. It essentially affects all versions of these Citrix products from 10.5 to 13.0.
According to researchers at Bad Packets, most of these servers are located in the United States (9,880), Germany (2,510), and the United Kingdom (2,028), with the most vulnerable endpoints located in the United States. They include military and government systems, schools, hospitals and health care providers, utilities, financial institutions, and “numerous Fortune 500 companies,” according to threat researchers.
“Given the ongoing scanning activity detected by security researcher Kevin Beaumont and SANS ISC since January 8, 2020 — it’s likely attackers have enumerated all publicly accessible Citrix ADC and Citrix (NetScaler) Gateway endpoints vulnerable to CVE-2019-19781,” according to a Bad Packets blog post. Beaumont dubbed the flaw “Shitrix.”
A group called Project Zero India released a proof-of-concept (PoC) exploit code for this vulnerability on Github. Shortly after that, security research group TrustedSec released another PoC exploit.
Comments