Citrix Federated Authentication Service (FAS)
CVE-2022-26355
Key Information:
- Vendor
Citrix
- Vendor
- CVE Published:
- 10 March 2022
What is CVE-2022-26355?
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Federated Authentication Service (FAS) <= 10.6
Federated Authentication Service (FAS) 7.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved