// For flags

CVE-2022-27518

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

Unauthenticated remote arbitrary code execution

Ejecución remota de código arbitrario no autenticado

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-03-21 CVE Reserved
  • 2022-12-13 CVE Published
  • 2022-12-13 Exploited in Wild
  • 2023-01-03 KEV Due Date
  • 2024-07-20 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- First Exploit
CWE
  • CWE-664: Improper Control of a Resource Through its Lifetime
CAPEC
  • CAPEC-253: Remote Code Inclusion
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Citrix
Search vendor "Citrix"
Application Delivery Controller Firmware
Search vendor "Citrix" for product "Application Delivery Controller Firmware"
>= 12.1 < 12.1-55.291
Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 12.1 < 12.1-55.291"
fips
Affected
in Citrix
Search vendor "Citrix"
Application Delivery Controller
Search vendor "Citrix" for product "Application Delivery Controller"
--
Safe
Citrix
Search vendor "Citrix"
Application Delivery Controller Firmware
Search vendor "Citrix" for product "Application Delivery Controller Firmware"
>= 12.1 < 12.1-55.291
Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 12.1 < 12.1-55.291"
ndcpp
Affected
in Citrix
Search vendor "Citrix"
Application Delivery Controller
Search vendor "Citrix" for product "Application Delivery Controller"
--
Safe
Citrix
Search vendor "Citrix"
Application Delivery Controller Firmware
Search vendor "Citrix" for product "Application Delivery Controller Firmware"
>= 12.1 < 12.1-65.25
Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 12.1 < 12.1-65.25"
-
Affected
in Citrix
Search vendor "Citrix"
Application Delivery Controller
Search vendor "Citrix" for product "Application Delivery Controller"
--
Safe
Citrix
Search vendor "Citrix"
Application Delivery Controller Firmware
Search vendor "Citrix" for product "Application Delivery Controller Firmware"
>= 13.0 < 13.0-58.32
Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 13.0 < 13.0-58.32"
-
Affected
in Citrix
Search vendor "Citrix"
Application Delivery Controller
Search vendor "Citrix" for product "Application Delivery Controller"
--
Safe
Citrix
Search vendor "Citrix"
Gateway Firmware
Search vendor "Citrix" for product "Gateway Firmware"
>= 12.1 < 12.1-65.25
Search vendor "Citrix" for product "Gateway Firmware" and version " >= 12.1 < 12.1-65.25"
-
Affected
in Citrix
Search vendor "Citrix"
Gateway
Search vendor "Citrix" for product "Gateway"
--
Safe
Citrix
Search vendor "Citrix"
Gateway Firmware
Search vendor "Citrix" for product "Gateway Firmware"
>= 13.0 < 13.0-58.32
Search vendor "Citrix" for product "Gateway Firmware" and version " >= 13.0 < 13.0-58.32"
-
Affected
in Citrix
Search vendor "Citrix"
Gateway
Search vendor "Citrix" for product "Gateway"
--
Safe