Please ensure Javascript is enabled for purposes of website accessibility
Portal oficial del Gobierno de Puerto Rico. 
Un sitio web oficial .pr.gov pertenece a una organización oficial del Gobierno de Puerto Rico.
Los sitios web seguros .pr.gov usan HTTPS, lo que significa que usted se conectó de forma segura a un sitio web.

TECNOLOGÍA

Gobierno de Puerto Rico

Alerta de ciberseguidad

Puerto Rico Innovation & Technology Service

Date:

June 14, 2022

A Vulnerability in Citrix Application Delivery Management (Citrix ADM) Could Allow for an Unauthenticated Attacker to Reset the Administrator Password - PATCH: NOW-

Gobierno:
High
Medium
Low
Negocios:
High
Medium
Low
Hogar:
High
Medium
Low

Multiple vulnerabilities have been discovered in Citrix ADM. Citrix ADM is a web-based solution for managing all Citrix deployments. The most severe of these vulnerabilities Could Allow for an Unauthenticated Attacker to Reset the Administrator Password.

SYSTEMS AFFECTED:

  • Citrix ADM 13.1 before 13.1-21.53
  • Citrix ADM 13.0 before 13.0-85.19

RISK:

Government:

  • Large and medium government entities: High
  • Small government entities: Medium

 

Businesses:

  • Large and medium business entities: High
  • Small business entities: Medium

Home users: Low

TECHNICAL SUMMARY:

Multiple vulnerabilities have been discovered in Citrix ADM. The most severe of these vulnerabilities Could Allow for an Unauthenticated Attacker to Reset the Administrator Password.

TacticInitial Access (TA0001):

Technique: Exploit Public-Facing Application (T1190):


  • Corruption of the system by a remote, unauthenticated user. The impact of this can include     the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted. (CVE-2022-27511)
  • Temporary disruption of the ADM license service. The impact of this includes preventing new     licenses from being issued or renewed by Citrix ADM. (CVE-2022-27512)