{"id":3438,"date":"2024-05-06T19:18:29","date_gmt":"2024-05-07T00:18:29","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway"},"modified":"2024-05-06T19:18:29","modified_gmt":"2024-05-07T00:18:29","slug":"citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/06\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway\/","title":{"rendered":"Citrix Addresses High-Severity Flaw in NetScaler ADC and Gateway"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbd5d4d98e91b7f6b\/66395b00d8cc384ff4ea2e33\/citrix_Ken_Wolter_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Citrix appears to have quietly addressed a vulnerability in its NetScaler Application Delivery Control (ADC) and Gateway appliances that gave remote, unauthenticated attackers a way to obtain potentially sensitive information from the memory of affected systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The bug was nearly identical to \u2014 but not as serious as \u2014 &#8220;CitrixBleed&#8221; (CVE-2023-4966), a critical zero-day vulnerability in the same two technologies that Citrix disclosed last year, according to researchers at Bishop Fox, who discovered and reported the flaw to Citrix in January.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Like CitrixBleed, But Not as Serious\">Like CitrixBleed, But Not as Serious<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers exploited <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/critical-citrix-bug-exploited-zero-day-patching-not-enough\" rel=\"noopener\">CitrixBleed<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> widely to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/citrixbleed-linked-to-ransomware-hit-on-china-s-state-owned-bank\" rel=\"noopener\">deploy ransomware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, steal information, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/citrix-bleed-bug-inflicts-mounting-wounds-cisa-warns\" rel=\"noopener\">other malicious purposes<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed\" rel=\"noopener\">Cybersecurity and Infrastructure Security Agency (CISA)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> was among many that urged affected organizations to quickly update their systems to patched versions of NetScaler, citing reports of widespread attacks that targeted the vulnerability. Boeing and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/comcast-xfinity-breached-citrix-bleed-35m-customers\" rel=\"noopener\">Comcast Xfinity<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> were among several major organizations that attackers targeted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In contrast, the flaw that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/bishopfox.com\/blog\/netscaler-adc-and-gateway-advisory\" rel=\"noopener\">Bishop Fox discovered<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in January was less dangerous because attackers would have been less likely to retrieve any information of high value from a vulnerable system with it. Even so, the bug \u2014 in NetScaler version 13.1-50.23 \u2014 did leave the door open for an attacker to occasionally capture sensitive information, including HTTP request bodies from the process memory of affected appliances, Bishop Fox said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The company also said Citrix acknowledged its vulnerability disclosure on Feb. 1. But Citrix did not assign the flaw a CVE identifier because it had already addressed the issue in NetScaler version 13.1-51.15, prior to disclosure, Bishop Fox said. It&#8217;s not clear if Citrix privately disclosed the vulnerability to customers at any time, or if it even considered the issue that Bishop Fox raised as a vulnerability. Bishop Fox itself said there&#8217;s been no public disclosure of the flaw until now.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Citrix did not respond immediately to a Dark Reading request for clarification on when, or if, the company disclosed the flaw prior to addressing it in version 13.1-51.15.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Out-of-Bounds Memory Issue\">Out-of-Bounds Memory Issue<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a blog this week, Bishop Fox identified the vulnerability it discovered as an unauthenticated out-of-bounds memory issue, which basically amounts to bugs that allow an attacker to access memory locations beyond the intended boundaries of a program. Bishop Fox said its researchers exploited the vulnerability to capture sensitive information, including HTTP request bodies from an affected appliance&#8217;s memory. The blog post read, &#8220;This could potentially allow attackers to obtain credentials submitted by users logging in to NetScaler ADC and Gateway appliances, or cryptographic material used by the appliance.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As with CitrixBleed, the flaw that Bishop Fox discovered affected NetScaler components when used for remote access and as authentication, authorization, and auditing (AAA) servers. Specifically, the security vendor found the Gateway and AAA virtual server to be handling HTTP host request headers in an unsafe manner, which was the same underlying cause for CitrixBleed. The company&#8217;s proof-of-concept code demonstrated how a remote adversary could exploit the vulnerability to retrieve potentially useful information for an attack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Bishop Fox staff analyzed vulnerable Citrix deployments and observed instances where the disclosed memory contained data from HTTP requests, sometimes including POST request bodies,&#8221; the company noted. Bishop Fox recommended that organizations running the affected NetScaler version upgrade to Version 13.1-51.15 or beyond.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Citrix appears to have quietly addressed a vulnerability in its<\/p>\n","protected":false},"author":12,"featured_media":3439,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3438","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=1000%2C539&ssl=1",1000,539,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=300%2C162&ssl=1",300,162,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=640%2C345&ssl=1",640,345,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=640%2C345&ssl=1",640,345,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=1000%2C539&ssl=1",1000,539,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=1000%2C539&ssl=1",1000,539,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=1000%2C539&ssl=1",1000,539,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?resize=825%2C539&ssl=1",825,539,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/citrix-addresses-high-severity-flaw-in-netscaler-adc-and-gateway.jpg?fit=1000%2C539&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3438"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3438\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3439"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}