CVE-2022-27510, CVE-2022-27518 – Measuring Citrix ADC & Gateway version adoption on the Internet
ID: 3a73bf45-37b9-5a07-892e-ea44539d47e3
STIX ID: report--3a73bf45-37b9-5a07-892e-ea44539d47e3
Feed Name: Fox-IT blog
This blog details a methodology to identify exact Citrix ADC and Gateway versions by extracting version-hash values from /vpn/index.html, acquiring Google Cloud Marketplace disk images, using gzip timestamps to infer build dates, and enumerating Citrix download URLs to recover missing builds; the authors mapped hashes to versions and produced internet-wide statistics to assess exposure to CVE-2022-27510 (authentication bypass) and CVE-2022-27518 (unauthenticated remote code execution), noting active exploitation by APT5 and that a non-trivial population of servers remains potentially vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
