CVE-2022-27518
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
6.9%
93.7th percentile
CISA KEV
Listed
Added 2022-12-13 · patch by 2023-01-03
Weakness / dates
—
Published — · modified —
Timeline
- 2022-12-13 — Added to CISA KEV (actively exploited)
- 2023-01-03 — CISA patch-by deadline
Description
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.