Health IT Security December 20, 2022
HC3 urged healthcare organizations to prioritize patching known cybersecurity vulnerabilities found in the Citrix Application Delivery Controller and Gateway platforms.
– Citrix released patches for a critical zero-day cybersecurity vulnerability (CVE-2022-27518) in its Application Delivery Controller (ADC) and Gateway platforms.
HHS knows of healthcare entities that have been compromised by the exploitation of this vulnerability, a sector alert from the Health Sector Cybersecurity Coordination Center (HC3) stated. HC3 urged healthcare and public health organizations to implement these patches immediately.
The vulnerability, which has been known to be exploited by a “highly capable state-sponsored adversary,” allows an unauthenticated party to execute commands remotely on vulnerable devices in order to compromise an entire system.