Citrix Vulnerability Advisory | July 2023

Citrix confirmed a critical vulnerability in NetScaler Gateway and NetScaler ADC products. Here's what you need to know.

Background

On July 18, 2023, Citrix released an advisory detailing a critical security flaw in NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC (formerly Citrix Application Delivery Controller). NetScaler Gateway is commonly used as a remote access solution and NetScaler ADC is a networking appliance for web applications. The security flaw (CVE-2023-3519) allows a remote, unauthenticated attacker to perform arbitrary code execution. Citrix reports that this vulnerability is being actively exploited by attackers. A security patch has been released and should be applied as soon as possible.

The vulnerabilities affect the following products and versions:

  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13 
  • NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.13 
  • NetScaler ADC 13.1-FIPS before 13.1-37.159
  • NetScaler ADC 12.1-FIPS before 12.1-55.297
  • NetScaler ADC 12.1-NDcPP before 12.1-55.297

Note: NetScaler ADC and NetScaler Gateway version 12.1 is now End Of Life (EOL) and is vulnerable.

This bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway. Customers using Citrix-managed cloud services or Citrix-managed Adaptive Authentication do not need to take any action.

Impact

Without a security patch, an unauthenticated remote attacker may be able to gain access to an affected Gateway or ADC appliance and execute arbitrary code. From there the attacker could move around the network and conduct further exploitation. Corvus has observed similar vulnerabilities lead to ransomware attacks.

Next steps for Citrix customers:

  1. Upgrade to a non-vulnerable version of ADC or Gateway as soon as possible:
    • NetScaler ADC and NetScaler Gateway 13.1-49.13  and later releases
    • NetScaler ADC and NetScaler Gateway 13.0-91.13  and later releases of 13.0  
    • NetScaler ADC 13.1-FIPS 13.1-37.159 and later releases of 13.1-FIPS  
    • NetScaler ADC 12.1-FIPS 12.1-55.297 and later releases of 12.1-FIPS  
    • NetScaler ADC 12.1-NDcPP 12.1-55.297 and later releases of 12.1-NDcPP 
    Note: Please note that Citrix ADC and Citrix Gateway versions prior to 12.1 are End of Life (EOL). Customers are recommended to upgrade their appliances to one of the supported versions that address the vulnerabilities.
  2. Cybersecurity firm, Mandiant, has released a tool that can be used to check for indicators of compromise on Citrix appliances (https://github.com/mandiant/citrix-ioc-scanner-cve-2023-3519/).

Resources

https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467