Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix urges admins to patch new NetScaler flaws as soon as possible

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
1 Posts 1 Posters 7 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Citrix is urging administrators to prioritize patching two newly disclosed vulnerabilities affecting its NetScaler Gateway and NetScaler ADC products. The company has issued an advisory stressing the need for immediate action, as these flaws could expose enterprise networks to significant risk if left unaddressed.

    The first issue involves a reflected cross-site scripting (XSS) vulnerability, while the second is a more severe privilege escalation flaw. According to the advisory, successful exploitation of the privilege escalation bug could allow an authenticated attacker to gain elevated rights on the appliance, potentially leading to full system compromise. While the XSS flaw requires user interaction, it could still be leveraged to execute malicious scripts in the context of the victim’s session.

    Affected versions include specific builds of NetScaler Gateway and NetScaler ADC (formerly Citrix ADC and Gateway). Citrix has released updated versions that resolve both issues, and the company strongly recommends upgrading to the latest available firmware. In the absence of an immediate patch, administrators are advised to apply the mitigation steps outlined in the official security bulletin, which include restricting access to management interfaces and reviewing current authentication policies.

    • Affected products: NetScaler Gateway (all supported versions before the fixed release) and NetScaler ADC (all supported versions before the fixed release).
    • Fixed versions: Available in the latest firmware updates from Citrix; check the advisory for your specific platform and build.
    • Temporary workaround: Limit exposure by restricting network access to the management interface and enforcing multi-factor authentication (MFA) on all user sessions.

    Given the critical nature of these appliances as remote access entry points, Citrix has emphasized that exploitation may be straightforward in some configurations. Organizations using these products should prioritize testing and deploying the patches immediately, as threat actors are likely to attempt exploitation in the coming days.

    Source: BleepingComputer

    Are your NetScaler appliances fully patched, and what steps are you taking to verify that no unauthorized access has already occurred?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World