NetScaler ADC 및 NetScaler Gateway가 Gateway(VPN virtual server, ICA Proxy, CVPN, RDP Proxy) 또는 AAA virtual server로 구성된 경우 민감한 정보가 노출됩니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
영향 제품·버전
제품 Citrix NetScaler ADC, NetScaler Gateway, netscaler application delivery controller
Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.
Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 Citrix NetScaler ADC, NetScaler Gateway, netscaler application delivery controller 12.1-55.300, 13.0-92.19, 13.1-37.164, 13.1-49.15, 14.1-8.50 기준을 충족하는지 확인합니다. 이어서 메모리 손상 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.