Citrix issues critical security updates for its NetScaler devices
Brief
Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass.
Citrix said in an advisory that supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances, are affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already been updated.
However, it added, “at this point [August 19] the NetScaler images available on cloud marketplaces (AWS, Azure, GCP) have not been updated.
