CISA KEV · Known exploitedHigh

CVE-2023-4966

Citrix NetScaler ADC, NetScaler Gateway, netscaler application delivery controller

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

CVSS
7.5
EPSS
100.0%
100.0% percentile
CISA KEV
Listed
Published
2023.10.10
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability100.0%
Technical severityCVSS 7.5

Vulnerability overview

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Affected product and versions

Product
Citrix NetScaler ADC, NetScaler Gateway, netscaler application delivery controller
Affected versions
>= 14.1 < 8.50, >= 13.1 < 49.15, >= 13.0 < 92.19, >= 13.1-FIPS < 37.164, >= 12.1-FIPS < 55.300, >= 12.1-NDcPP < 55.300, >= 12.1 < 12.1-55.300, >= 13.0 < 13.0-92.19, >= 13.1 < 13.1-37.164, >= 13.1 < 13.1-49.15, >= 14.1 < 14.1-8.50
Fixed versions
12.1-55.300, 13.0-92.19, 13.1-37.164, 13.1-49.15, 14.1-8.50

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.

Due date: 2023.11.08
  1. 1
    Identify

    Confirm that Citrix NetScaler ADC, NetScaler Gateway, netscaler application delivery controller and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-119
KEV added
2023.10.18
Ransomware use
확인됨
CVE-2023-4966 — Citrix NetScaler ADC, NetScaler Gateway, netscaler application delivery controller | SECUFOCUS NOW