Sophos' putrid patch snuffs Citrix kit, kills call centre

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
A Sophos Web Appliance update has crashed users' PC fleets including knocking offline the Australian call centre of a global company for two days after support was quietly revoked for SSL 3.0 ciphers used in Citrix Receiver.

The British security firm pushed out update version 4.0.2.3 last week to correct four non-critical issues and an undocumented blocking of SSL 3.0.

Sophos has been contacted for comment.

That update killed all but the latest versions of Citrix Receiver. The new Citrix offering was updated to ward off POODLE downgrade attacks.

Correspondence between Sophos and its customers seen by El Reg reveals the company has fielded multiple complaints from users caught off-guard by the mess.

The Australian contact centre for a large unnamed international organisation was knocked offline for two days - and is still enduring some outages - after the update prevented operators from accessing a portal required to make mission-critical entries.

That crash hit without warning according to a system administrator caught up in the mess and who requested anonymity.

The admin says Sophos did not warn of its SSL 3.0 revocation and took 24 hours to respond with an answer to his queries.

The Sophos update could not be rolled-back forcing the admin to undergo unplanned complex Citrix upgrade late last week across the three global sites, an operation that is still ongoing.

He says that upgrade would normally be planned and coordinated in advance.

The admin faced questions from concerned senior management and while he thanked some helpful Sophos engineers has asked the vendor to apologise
 
  • Like
Reactions: Ink and Sr. Normal

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
Perhaps the moral of this article could be "Upgrades, like powerful prescriptive medications, may have 'occasional' adverse side :eek:effects:confused:o_O! :oops:
 
  • Like
Reactions: Sr. Normal
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top