Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jan 3, 2023

CVE-2022-27518

High
EPSS 23.0%CISA KEV
Citrix/Application Delivery Controller (ADC) and Gateway

Description

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

EPSS — Exploit Probability

23.0%

Higher than 95.8% of all CVEs

Required Action

https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/; https://nvd.nist.gov/vuln/detail/CVE-2022-27518

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
23.0%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Dec 13, 2022

Added to KEV

Dec 13, 2022

Remediation Due

Jan 3, 2023

Affected Product

Citrix

Application Delivery Controller (ADC) and Gateway

View all Citrix CVEs