CVE-2022-27518: Citrix Application Delivery Controller (ADC) and Gateway
EPSS6.6%No. 1371 of 1739 in KEV
CVE year2022listed the same year
Same vendor in KEV27
Same product1
| Field | Value |
|---|---|
| Vendor | Citrix |
| Product | Application Delivery Controller (ADC) and Gateway |
| Name | Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability |
| Added to KEV | 2022-12-13 |
| US federal due date | 2023-01-03 |
| Ransomware use | Unknown |
| CWE | CWE-664 |
CISA description
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Citrix Application Delivery Controller (ADC) and Gateway vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-12-13.