Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Cybercriminals scan Network for vulnerable Citrix systems

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,905
Reaction score
942
Points
212
Awards
2
  • trusted user
  • Rich User
Citrix previously fixed 11 vulnerabilities in its Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP products.




Cybercriminals allegedly scan the Internet for Citrix systems containing recently discovered vulnerabilities. A few days ago, SecurityLab wrote that Citrix fixed 11 vulnerabilities in its products Citrix ADC (formerly NetScaler ADC), Citrix Gateway (formerly NetScaler Gateway) and Citrix SD-WAN WANOP (models 4000-WO, 4100-WO, 5000- WO and 5100-WO). Problems can be exploited for privilege escalation, authorization bypass, code injection, and DoS and XSS attacks.

Although some of the vulnerabilities could be exploited remotely without authentication, the provider noted that exploiting many problems requires access to the target system, user interaction, or other preconditions.

According to Citrix specialist Fermin J. Serna on the company's blog, recently discovered vulnerabilities are less dangerous compared to the critical issue (CVE-2019-19781) identified in December last year. According to Serna, the new problems are completely eliminated by corrections, unlike CVE-2019-19781, for which the company initially issued only temporary measures to prevent the exploitation of the vulnerability.

Johannes Ullrich, a specialist at SANS Institute of Technology, said his hanipot, designed to intercept attacks on F5 Networks' BIG-IP systems, recorded attempts to exploit two recently discovered vulnerabilities in Citrix products. Attackers tried to download files and gain access to confidential information. According to the expert, the attacks were carried out as part of a network scan for vulnerable Citrix systems. It remains unknown which of the 11 problems are targeted, but Ulrich considers the most likely candidates CVE-2020-8195 and CVE-2020-8196. Both problems are disclosure vulnerabilities, and their operation requires authentication by NSIP, the IP address at which the Citrix ADC can be accessed for management.
 
Ad End 1 February 2024
Top