CVE-2022-27510 is a critical authentication bypass vulnerability affecting Citrix Application Delivery Controller (ADC) and Gateway products, allowing unauthorized access to Gateway user capabilities. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, including reports of active exploitation by the Royal ransomware group. Organizations are urged to patch immediately to mitigate the high risk of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-65.21CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.0-88.12CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 13.1, < 13.1-33.41CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 12.1, < 12.1-65.21CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:-:*:*:* | ||
>= 13.0, < 13.0-88.12CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.