AA20-020A: Critical Vulnerability in Citrix Application Delivery Controller, Gateway, and SD-WAN WANOP

Original release date: January 20, 2020<br/><h3>Summary</h3><p>On January 19, 2020, Citrix released firmware updates for Citrix Application Delivery Controller (ADC) and Citrix Gateway versions 11.1 and 12.0 to address CVE-2019-19781. Citrix expects to release updates for other vulnerable versions of Citrix ADC, Gateway, and SD-WAN WANOP appliances through January 24, 2020. (See Mitigations for update schedule).<a href=”https://support.citrix.com/article/CTX267027″>[1]</a></p> <p>A remote, unauthenticated attacker could exploit CVE-2019-19781 to perform arbitrary code execution.<a href=”https://support.citrix.com/article/CTX267027″>[2]</a> This vulnerability has been detected in exploits in the wild.<a href=”https://www.ncsc.gov.uk/news/citrix-alert”>[3]</a></p> <p>The Cybersecurity and Infrastructure Agency (CISA) strongly recommends that all users and administrators upgrade their vulnerable appliances as soon as possible once the appropriate firmware update becomes available.</p> <h4>Timeline of Specific Events</h4> <ul> <li>December 17, 2019 – Citrix releases Security Bulletin CTX267027 with mitigations steps.</li> <li>January 8, 2020 – The CERT Coordination Center (CERT/CC) releases Vulnerability Note VU#619785: Citrix Application Delivery Controller and Citrix Gateway Web Server Vulnerability, <a href=”https://www.kb.cert.org/vuls/id/619785/”>[4]</a> and CISA releases a Current Activity entry.<a href=”https://www.us-cert.gov/ncas/current-activity/2020/01/08/citrix-application-delivery-controller-and-citrix-gateway”>[5]</a></li> <li>January 10, 2020 – The National Security Agency (NSA) releases a Cybersecurity Advisory on CVE-2019-19781.<a href=”https://media.defense.gov/2020/Jan/10/2002233132/-1/-1/0/CSA%20FOR%20CITRIXADCANDCITRIXGATEWAY_20200109.PDF”>[6]</a></li> <li>January 11, 2020 – Citrix releases blog post on CVE-2019-19781 with timeline for fixes.<a href=”https://www.citrix.com/blogs/2020/01/11/citrix-provides-update-on-citrix-adc-citrix-gateway-vulnerability/”>[7]</a></li> <li>January 13, 2020 – CISA releases a Current Activity entry describing their utility that enables users and administrators to test whether their Citrix ADC and Citrix Gateway firmware is susceptible to the CVE-2019-19781 vulnerability.<a href=”https://www.us-cert.gov/ncas/current-activity/2020/01/13/cisa-releases-test-citrix-adc-and-gateway-vulnerability”>[8]</a>&nbsp;</li> <li>January 16, 2020 – Citrix announces that Citrix SD-WAN WANOP appliance is also vulnerable to CVE-2019-19781.</li> <li>January 19, 2020 – Citrix releases firmware updates for Citrix ADC and Citrix Gateway versions 11.1 and 12.0 and blog post on accelerated schedule for fixes.<a href=”https://www.citrix.com/blogs/2020/01/19/vulnerability-update-first-permanent-fixes-available-timeline-accelerated/”>[9]</a></li> <li>January 24, 2020 – Citrix expects to release firmware updates for Citrix ADC and Citrix Gateway versions 10.5, 12.1, and 13.0 and Citrix SD-WAN WANOP release 10.2.6 and 11.0.3.</li> </ul> <h3>Technical Details</h3><h4>Impact</h4> <p>On December 17, 2019, Citrix reported vulnerability CVE-2019-19781. A remote, unauthenticated attacker could exploit this vulnerability to perform arbitrary code execution. This vulnerability has been detected in exploits in the wild.</p> <p>The vulnerability affects the following appliances:</p> <ul> <li>Citrix NetScaler ADC and NetScaler Gateway version 10.5 – all supported builds</li> <li>Citrix ADC and NetScaler Gateway version 11.1 – all supported builds before 11.1.63.15</li> <li>Citrix ADC and NetScaler Gateway version 12.0 – all supported builds before 12.0.63.13</li> <li>Citrix ADC and NetScaler Gateway version 12.1 – all supported builds</li> <li>Citrix ADC and Citrix Gateway version 13.0 – all supported builds</li> <li>Citrix SD-WAN WANOP firmware and appliance models 4000, 4100, 5000, and 5100 – all supported builds. (Citrix SD-WAN WANOP is vulnerable because it packages Citrix ADC as a load balancer).</li> </ul> <h4>Detection Measures</h4> <p>CISA has released a utility that enables users and administrators to detect whether their Citrix ADC and Citrix Gateway firmware is susceptible to CVE-2019-19781.<a href=”https://www.us-cert.gov/ncas/current-activity/2020/01/13/cisa-releases-test-citrix-adc-and-gateway-vulnerability”>[10] </a>CISA encourages administrators to visit CISA’s <a href=”https://github.com/cisagov/check-cve-2019-19781″>GitHub page</a> to download and run the tool.</p> <p>See the National Security Agency’s Cybersecurity Advisory on CVE-2020-19781 for other detection measures.<a href=”https://media.defense.gov/2020/Jan/10/2002233132/-1/-1/0/CSA%20FOR%20CITRIXADCANDCITRIXGATEWAY_20200109.PDF”>[11]</a></p> <h3>Mitigations</h3><p>CISA strongly recommends users and administrators update Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP once…

Continue Reading — AA20-020A: Critical Vulnerability in Citrix Application Delivery Controller, Gateway, and SD-WAN WANOP

What is in your mind, about this post ? Leave a Reply

Close
  Our next learning article is ready, subscribe it in your email

What is your Learning Goal for Next Six Months ? Talk to us