Skip to content
COOEY

EXPOSURES › CVE-2022-27518

CVE-2022-27518

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-12-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-27518 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Citrix ADC & Gateway AD auth bypass exploited

Citrix's ADC & Gateway allowed unauthorized code execution due to an authentication bypass vulnerability, impacting organizations using SAML SP or IdP configurations.

Shame score — Critical security track record with multiple high-severity vulnerabilities, including an actively exploited RCE 0-day.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized