CVE-2022-27513: Remote desktop takeover via phishing
Published Nov 8, 2022
·Updated
Remote desktop takeover via phishing
Affected Software
9 affected components
Citrix Gateway>=12.1<12.1-65.21
Citrix Gateway>=13.0<13.0-88.12
Citrix Gateway>=13.1<13.1-33.41
Citrix Application Delivery Controller Firmware>=12.1<12.1-65.21
Citrix Application Delivery Controller Firmware>=13.0<13.0-88.12
Citrix Application Delivery Controller Firmware>=13.1<13.1-33.47
Citrix Application Delivery Controller
Citrix Application Delivery Controller Firmware>=12.1<12.1-55.289
Citrix Application Delivery Controller Firmware>=12.1<12.1-55.289
Event History
Nov 8, 2022
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-27513?
CVE-2022-27513 is a vulnerability that allows attackers to take control of remote desktops through phishing attacks.
2
What is the severity of CVE-2022-27513?
CVE-2022-27513 has a severity rating of 9.6, which is considered critical.
3
Which software is affected by CVE-2022-27513?
Citrix Gateway versions 12.1-65.21 to 12.1-65.21, 13.0-88.12 to 13.0-88.12, and 13.1-33.41 to 13.1-33.41, as well as Citrix Application Delivery Controller Firmware versions 12.1-65.21 to 12.1-65.21, 13.0-88.12 to 13.0-88.12, and 13.1-33.47 to 13.1-33.47 are affected by CVE-2022-27513.
4
How can an attacker exploit CVE-2022-27513?
An attacker can exploit CVE-2022-27513 by tricking users into clicking on malicious links or downloading malicious files through phishing emails or websites.
5
Is Citrix Application Delivery Controller vulnerable to CVE-2022-27513?
No, Citrix Application Delivery Controller is not vulnerable to CVE-2022-27513.