Citrix Confirms Ongoing DDoS Attack Impacting NetScaler ADCs

Citrix Confirms Ongoing DDoS Attack Impacting NetScaler ADCs

Citrix has confirmed today that an ongoing ‘DDoS attack pattern’ using DTLS as an amplification vector is affecting Citrix Application Delivery Controller (ADC) networking appliances with EDT enabled.

Datagram Transport Layer Security (DTLS) is a communications protocol for securing delay-sensitive apps and services that use datagram transport.

DTLS is based on the Transport Layer Security (TLS) protocol and it is designed to prevent eavesdropping and tampering, and to protect data privacy.

Reports of the attack have started trickling in on December 21st, with customers reporting an ongoing DDOS amplify attack over UDP/443 against Citrix (NetScaler) Gateway devices.

Also Read: Limiting Location Data Exposure: 8 Best Practices

Small number of customers affected

“As part of this attack, an attacker or bots can overwhelm the Citrix ADC DTLS network throughput, potentially leading to outbound bandwidth exhaustion,” the company explained in a threat advisory published earlier today.

“The effect of this attack appears to be more prominent on connections with limited bandwidth.”

The scope of the attack is limited to just “a small number of customers” at the moment according to Citrix and it impacts all ADCs with Enlightened Data Transport UDP Protocol (EDT) enabled.

Furthermore, based on current evidence there are no known Citrix vulnerabilities being actively exploited in this ongoing attack.

If information on products vulnerable to DDoS attacks due to software bugs is discovered during this investigation, it will be published by the Citrix Security Response Team in a separate security advisory.

Update to remove attack vector under development

“Citrix is working on a feature enhancement in DTLS to eliminate the susceptibility to this attack,” the company added.

“Citrix expects to have this enhancement available on the Citrix downloads page for all supported versions on Jan 12, 2021.”

Customers impacted by this DDoS attack can temporarily mitigate it by temporarily disabling DTLS, the amplification vector used by the attackers.

To disable DTLS on your Citrix ADC you will have to issue the following command from the command line interface:

set vpn vserver -dtls OFF

“Disabling the DTLS protocol may lead to limited performance degradation to real time applications using DTLS in your environment,” Citrix added.

Also Read: 10 Practical Benefits of Managed IT Services

“The extent of degradation depends on multiple variables. If your environment does not use DTLS, disabling the protocol temporarily will have no performance impact.”

Customers who can’t immediately disable DTLS in their environment are advised to reach out to Citrix Technical Support.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago