Vulnerability in Citrix Servers
Citrix, a cloud computing and virtualization company is used by companies including Microsoft, Google, and SAP. One of its flagship products is Citrix Workspace, a virtualization platform that helps enterprises deploy apps and desktops remotely, including securing all the devices that connect to a network. Over the past three decades, Citrix has established itself as the clear leader in secure hybrid work.
Citrix merged with TIBCO Software under the newly formed Cloud Software Group. Citrix spun off the re-branded Citrix ADC back into a standalone entity Netscaler under the same parent. A report says, thousands of Citrix servers are still unpatched for critical security vulnerabilities.
Industry was expecting that, post-acquisition, together with Tibco, they would be able to operate with greater scale and provide a larger customer base with a broader range of solutions to accelerate their digital transformations and enable them to deliver the future of hybrid work.
The recent news on thousands of Citrix ADC and Gateway deployments remain vulnerable to two critical-severity security issues that the vendor fixed in recent months. Researchers uncovered thousands of Citrix servers that are vulnerable to two critical flaws, one of which is being actively exploited by nation-state hackers. Netgear also warned its customers about a denial-of-service vulnerability affecting some of its devices.
Citrix and the US National Security Agency warned earlier this month that CVE-2022-27518 is actively being exploited in the wild by threat actors, including the China-linked state-sponsored group APT5.
Thousands of Internet-facing Citrix servers are still unpatched, making them an attractive target for hacking crews. According to the NSA, Chinese hackers are modifying legitimate binaries within Citrix ADC that are essential for running the application.
There are growing state-sponsored threat actors linked to China and Iran have leveraged the exploit for ransomware attacks, particularly targeting the healthcare industry. Both companies urged their respective customers to update their devices to the latest firmware as soon as possible.
The two vulnerabilities in Citrix servers tracked CVE-2022-27510 and CVE-2022-27518 affect Citrix ADC and Citrix Gateway, the company's cloud-based solutions for network traffic and access control.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.