A serious situation is developing around Citrix NetScaler ADC and Gateway. Managed service providers, MDR teams, and security organizations are reportedly advising customers to take internet-facing NetScaler appliances offline following warnings about two previously undisclosed vulnerabilities reportedly enabling unauthenticated remote code execution. What makes this particularly concerning is the timing. There are reportedly no public CVEs, no public patch, and limited technical details available so far. Organizations are reportedly being advised to shut down affected appliances rather than simply wait for a patch, with Citrix expected to release fixes early next week.

  • Ex Nummis@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    3 days ago

    When my old job still used Citrix for customers, 90% of our support calls would be about that. We spent, if that, 10% of the time actually troubleshooting our own software. Most of it was certificates included with Receiver not being fully validated or even being fucking revoked. Fun times.

  • Brkdncr@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 days ago

    Netscalers have always been Swiss cheese. No idea why they are or why they weren’t rebuilt from the ground up.