CVE-2023-4966
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
9Exploited in Wild
YesDecision
Descriptions
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA ?virtual?server.
Divulgación de información confidencial en NetScaler ADC y NetScaler Gateway cuando se configura como Gateway (servidor virtual VPN, ICA Proxy, CVPN, RDP Proxy) o servidor "virtual" AAA.
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-14 CVE Reserved
- 2023-10-10 CVE Published
- 2023-10-18 Exploited in Wild
- 2023-10-25 First Exploit
- 2023-11-08 KEV Due Date
- 2024-08-02 CVE Updated
- 2024-11-11 EPSS Updated
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (12)
URL | Date | SRC |
---|---|---|
https://github.com/Chocapikk/CVE-2023-4966 | 2023-10-26 | |
https://github.com/RevoltSecurities/CVE-2023-4966 | 2023-10-29 | |
https://github.com/byte4RR4Y/CVE-2023-4966 | 2023-11-27 | |
https://github.com/0xKayala/CVE-2023-4966 | 2023-10-28 | |
https://github.com/mlynchcogent/CVE-2023-4966-POC | 2023-10-25 | |
https://github.com/IceBreakerCode/CVE-2023-4966 | 2023-10-25 | |
https://github.com/s-bt/CVE-2023-4966 | 2023-11-20 | |
https://github.com/senpaisamp/Netscaler-CVE-2023-4966-POC | 2024-04-23 | |
https://github.com/LucasOneZ/CVE-2023-4966 | 2024-09-14 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.citrix.com/article/CTX579459 | 2024-06-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 12.1 < 12.1-55.300 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 12.1 < 12.1-55.300" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 12.1 < 12.1-55.300 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 12.1 < 12.1-55.300" | ndcpp |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.0 < 13.0-92.19 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.0 < 13.0-92.19" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.1 < 13.1-37.164 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.1 < 13.1-37.164" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.1 < 13.1-49.15 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.1 < 13.1-49.15" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 14.1 < 14.1-8.50 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 14.1 < 14.1-8.50" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 13.0 < 13.0-92.19 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 13.0 < 13.0-92.19" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 13.1 < 13.1-49.15 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 13.1 < 13.1-49.15" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 14.1 < 14.1-8.50 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 14.1 < 14.1-8.50" | - |
Affected
|