CVE-2023-4966KEV · OVERDUECWE-119

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Critical · published October 10, 2023

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.4. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1033
days past CISA
deadline
CVSS v3.1
9.4
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 Sensitive data could spill out like a secret recipe gone rogue! The misconfiguration in NetScaler ADC and Gateway allows attackers to snag sensitive info under certain conditions. 🔥 Think of it as a hotel that accidentally leaves its guest list out in the lobby—anyone could see the VIPs and their room numbers. This vulnerability lets attackers peek at sensitive information that should stay private, similar to a misplaced guest register. This could lead to devastating consequences, such as unauthorized access to confidential user information, credentials, or sensitive corporate data. Attackers exploiting this vulnerability might infiltrate your network, exposing your organization to severe risks and potential data breaches.

Put simply

Think of it as a hotel that accidentally leaves its guest list out in the lobby—anyone could see the VIPs and their room numbers. This vulnerability lets attackers peek at sensitive information that should stay private, similar to a misplaced guest register. CVE-2023-4966 is a sensitive information disclosure issue in NetScaler ADC and Gateway when configured as a VPN virtual server or AAA virtual server. It arises from improper handling of data, allowing unauthorized access to sensitive information under specific configurations.

What to do

This could lead to devastating consequences, such as unauthorized access to confidential user information, credentials, or sensitive corporate data. Attackers exploiting this vulnerability might infiltrate your network, exposing your organization to severe risks and potential data breaches. Act swiftly! Ensure you update your NetScaler ADC and NetScaler Gateway to the latest version to mitigate this vulnerability. Additionally, review your configuration settings to ensure no sensitive information is inadvertently disclosed. 🛡️ You've got this! With quick action and proper measures, you can safeguard your systems and keep your data secure! 💪✨

The record
Technical detail
CVSS v3.1
9.4 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.99999 · 100.0th percentile
Weakness
CWE-119 · Improper Restriction of Operations within the Bounds of a Memory Buffer
Published
2023-10-10T18:15Z
KEV added
2023-10-18 · due 2023-11-08
Affected products (9)
ProductVersionsFixed in
citrix/netscaler_application_delivery_controller≥ 12.1, < 12.1-55.30012.1-55.300
citrix/netscaler_application_delivery_controller≥ 12.1, < 12.1-55.30012.1-55.300
citrix/netscaler_application_delivery_controller≥ 13.0, < 13.0-92.1913.0-92.19
citrix/netscaler_application_delivery_controller≥ 13.1, < 13.1-37.16413.1-37.164
citrix/netscaler_application_delivery_controller≥ 13.1, < 13.1-49.1513.1-49.15
citrix/netscaler_application_delivery_controller≥ 14.1, < 14.1-8.5014.1-8.50
citrix/netscaler_gateway≥ 13.0, < 13.0-92.1913.0-92.19
citrix/netscaler_gateway≥ 13.1, < 13.1-49.1513.1-49.15
citrix/netscaler_gateway≥ 14.1, < 14.1-8.5014.1-8.50
References (5)
EPSS history
Timeline
  • 18 OCT 00:00Z
    Added to CISA KEV — remediate by Nov 8
    kev
  • 10 OCT 13:12Z
    Unauthenticated sensitive information disclosure
    cvelistv5