Customers vulnerable to attacks if CVE-2019-19781 not fixed Credit: Ipopba / Getty Images Telstra has urged business customers to fix an unpatched flaw in their Citrix systems three weeks after the vulnerability was first uncovered. The telco warned local enterprise users that hackers are actively scanning Citrix servers for gaps following the discovery of a vulnerability in the vendor’s Application Delivery Controller (ADC) and Gateway. More than 3,500 companies in Australia are vulnerable to attack, according to the UK-based security firm Positive Technologies, which discovered the flaw known as CVE-2019-19781. “It is important that customers are aware that a working exploit to this threat has been published on the internet and to take immediate action,” Clive Reeves, Telstra’s Deputy Chief Information Security Officer wrote in a blog post. The vulnerability affects all supported versions of the product and all supported platforms, including Citrix ADC and Citrix Gateway 13.0, Citrix ADC and NetScaler Gateway 12.1, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1, and also Citrix NetScaler ADC and NetScaler Gateway 10.5. If exploited, the flaw allows threat actors to conduct remote code execution (RCE) attacks, which gives them direct access to the local networks behind the gateways without an account or authentication. According to Reeves, this could result in cyber attacks including malware, ransomware, a denial of service or theft. The vulnerability remains as of yet unpatched, although Citrix has released mitigation steps which all users and customers are urged to take. Users are all advised to upgrade all their vulnerable applications to a fixed version of firmware when released towards the end of January. Related content brandpost Who’s paying your data integration tax? Reducing your data integration tax will get you one step closer to value—let’s start today. By Sandrine Ghosh Jun 05, 2023 4 mins Data Management feature 13 essential skills for accelerating digital transformation IT leaders too often find themselves behind on business-critical transformation efforts due to gaps in the technical, leadership, and business skills necessary to execute and drive change. By Stephanie Overby Jun 05, 2023 12 mins Digital Transformation IT Skills tip 3 things CIOs must do now to accurately hit net-zero targets More than a third of the world’s largest companies are making their net-zero targets public, yet nearly all will fail to hit them if they don’t double the pace of emissions reduction by 2030. This puts leading executives, CIOs in particul By Diana Bersohn and Mauricio Bermudez-Neubauer Jun 05, 2023 5 mins CIO Accenture Emerging Technology case study Merck Life Sciences banks on RPA to streamline regulatory compliance Automated bots assisted in compliance, thereby enabling the company to increase revenue and save precious human hours, freeing up staff for higher-level tasks. By Yashvendra Singh Jun 05, 2023 5 mins Digital Transformation Robotic Process Automation Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe