CVE-2022-27518 is a critical unauthenticated remote arbitrary code execution vulnerability affecting Citrix Application Delivery Controller (ADC) and Gateway products. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and multiple media reports, including exploitation by APT5. Despite the lack of public exploit code in Metasploit, Nuclei, or ExploitDB, its high FAUCET Risk Score of 99/100 and significant community discussion highlight the urgent need for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-55.291CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:fips:*:*:* | ||
>= 12.1, < 12.1-55.291CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:ndcpp:*:*:* | ||
>= 12.1, < 12.1-65.25CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.0-58.32CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 12.1, < 12.1-65.25CPE matchmatch criteria | cpe:2.3:o:citrix:gateway_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.