sb-as logo
Story image

15,000 companies still critically vulnerable from Citrix security flaws - report

A month and a half after Positive Technologies released its overview of a critical vulnerability in Citrix software that was endangering 80,000 companies in 158 countries, one out of every five companies have still not taken any action to fix this vulnerability, according to recent threat intelligence from Positive Technologies.
 
Critical vulnerability CVE-2019-19781 in Citrix Application Delivery Controller (NetScaler ADC) and Citrix Gateway (NetScaler Gateway) was discovered in December by Positive Technologies expert Mikhail Klyuchnikov. 

According to Positive Technologies data as of the end of 2019, the greatest number of potentially vulnerable organizations is located in the US (over 38% of all vulnerable organizations), as well as in Germany, the UK, the Netherlands, and Australia. 

On January 8, 2020, an exploit was released. It allowed a potential attacker to perform automatic attacks against companies that failed to fix the vulnerability.
 
Citrix developers planned to resolve the issue on January 27 through January 31 but released a series of patches for various product versions a week before that. 

Positive Technologies expert security center director Alexei Novikov says those affected should take every precaution.

“The necessary update must be installed as soon as possible,” says Novikov.

“Until then, follow the security recommendations by Citrix, available since the information about the vulnerability was released.” 
 
Overall, the vulnerability is being fixed relatively quickly, but 19% of companies are still at risk. 

The countries with the greatest numbers of vulnerable companies currently include Brazil (43% of all companies where the vulnerability was originally detected), China (39%), Russia (35%), France (34%), Italy (33%), and Spain (25%). 

The US, UK, and Australia are protecting themselves quicker, but they each have 21% of companies still using vulnerable devices without any protection measures.
 
If the vulnerability is exploited, attackers obtain direct access to the company's local network from the internet. 

This attack does not require access to any accounts and therefore can be performed by any external attacker.
 
To fend off potential attacks, companies can use web application firewalls. 

The system must be set to block all dangerous requests to ensure protection in real time. 

Considering how long this vulnerability has been around (the first vulnerable version of the software was released in 2014), detecting potential exploitation of this vulnerability and, therefore, infrastructure compromise retrospectively becomes just as important. 

Starting December 18, 2019, PT Network Attack Discovery users can use special rules detecting attempts to exploit this vulnerability online.

Story image
Forcepoint Dynamic Edge Protection delivers data-centric SASE solutions
The Dynamic Edge Protection suite includes new cloud security gateway and private access offerings through its SASE solution architecture.More
Story image
DDoS attacks surge 542% amidst COVID-19 pandemic - report
Generally considered the “off season” for DDoS attacks, researchers attribute the surge in incidents to malicious efforts during the COVID-19 pandemic.More
Story image
Internet outages drastically increased during COVID-19 lockdowns, report finds
Global internet disruptions increased 63% in March, with internet service providers hit the hardest. This is according to the 2020 Internet Performance Report from ThousandEyes, the internet and cloud intelligence company.More
Download image
Hardware Security Modules - and why they need to be virtualised
Unbound's vHSM provides advanced key management functionality, as well as easy and secure remote administration support - meaning there is no need for users to compromise on security any longer.More
Story image
A third of millennials think they're 'too boring' to be victim of cyber attack
While many millennials are concerned at how their data is being used and whether they are being targeted by cyber-attackers, according to Kaspersky any potential action taken to tighten their online security is at ‘the bottom of their to-do list’.More
Story image
CompTIA's new threat intelligence resource officially launches
The new resource is designed to help technology solution providers, managed services providers (MSPs) and other organisations searching for critical cybersecurity threat intelligence. More