Junglewise Threat Intelligence

CVE-2023-4966: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

CVE-2023-4966 · Severity: critical · CVSS 9.4 · Exploited in the wild · Published 2023-10-18

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway. Vendors: Citrix.

Executive brief

A buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway allows for sensitive information disclosure. The flaw is exploitable when the devices are configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Affected products

  • Citrix Systems, Inc. NetScaler ADC
  • Citrix Systems, Inc. NetScaler Gateway

Timeline

  • 2023-10-18: disclosed
  • 2023-10-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-18: advisory: Vendor advisory CTX579459 published

Related threats