On July 31st Citrix announced Security Vulnerabilities in Citrix Access Gateway Standard Edition with a Critical severity.
The following description was given to further explain the vulnerabilities:
Three security vulnerabilities have been identified in Access Gateway Standard Edition:
- Directory traversal in Access Gateway Standard Edition 5.0.x prior to version 5.0.4 (critical severity)
- Access Gateway Standard Edition 5.0.x can act as an open proxy (high severity)
- Text content injection in Access Gateway Standard Edition 5.0.3 and 5.0.4 (low severity)
Access Gateway Standard Edition versions 4.5.x and 4.6.x and currently supported versions of NetScaler Access Gateway Enterprise Edition are not affected by these vulnerabilities.
You are strongly adviced to install the related patch, which can be found at: http://support.citrix.com/article/CTX134257 on the affected appliances (both physical on the 2010 model and virtual on the VPX).
The following sources have been used to create this post:
CTX133648 – Security Vulnerabilities in Citrix Access Gateway Standard Edition
CTX134257 – Access Gateway 5.0 – Maintenance Release 5.0.4 (Patch_1_284097)
Pingback: virtuEs.IT
Pingback: Kees Baggerman