Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-4966— Unauthenticated sensitive information disclosure

Quick assessment

Affected
Citrix NetScaler ADC
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Citrix Systems Citrix NetScaler Gateway(Citrix Systems Gateway)和Citrix Systems NetScaler ADC都是美国思杰系统(Citrix Systems)公司的产品。Citrix NetScaler Gateway是一套安全的远程接入解决方案。该方案可为管理员提供应用级和数据级管控功能,以实现用户从任何地点远程访问应用和数据。Citrix Systems NetScaler ADC是一个应用程序交付和安全平台。 NetScale

CVSS 9.4 · Critical KEV · Ransomware EPSS 100.00% · P100

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 9

VendorProduct Version RangeStatus
Citrix NetScaler ADC 14.1< 8.50 affected
13.1< 49.15 affected
13.0< 92.19 affected
13.1-FIPS< 37.164 affected
12.1-FIPS< 55.300 affected
12.1-NDcPP< 55.300 affected
Citrix NetScaler Gateway 14.1< 8.50 affected
13.1< 49.15 affected
13.0< 92.19 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-4966

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated sensitive information disclosure
Source: CVE Program / CVE List V5
Vulnerability Description
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Citrix Systems NetScaler ADC和NetScaler Gateway 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Citrix Systems Citrix NetScaler Gateway(Citrix Systems Gateway)和Citrix Systems NetScaler ADC都是美国思杰系统(Citrix Systems)公司的产品。Citrix NetScaler Gateway是一套安全的远程接入解决方案。该方案可为管理员提供应用级和数据级管控功能,以实现用户从任何地点远程访问应用和数据。Citrix Systems NetScaler ADC是一个应用程序交付和安全平台。 NetScale
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Citrix NetScaler ADC 14.1 ~ 8.50 -
Citrix NetScaler Gateway 14.1 ~ 8.50 -

II. Public POCs for CVE-2023-4966

# POC Description Source Link Shenlong Link
1 Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. https://github.com/Chocapikk/CVE-2023-4966 POC Details
2 Citrix CVE-2023-4966 from assetnote modified for parallel and file handling https://github.com/dinosn/citrix_cve-2023-4966 POC Details
3 Proof Of Concept for te NetScaler Vuln https://github.com/mlynchcogent/CVE-2023-4966-POC POC Details
4 None https://github.com/IceBreakerCode/CVE-2023-4966 POC Details
5 Ansible Playbook for CVE-2023-4966 https://github.com/ditekshen/ansible-cve-2023-4966 POC Details
6 CVE-2023-4966 - NetScaler ADC and NetScaler Gateway Memory Leak Exploit https://github.com/0xKayala/CVE-2023-4966 POC Details
7 Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation https://github.com/certat/citrix-logchecker POC Details
8 An Exploitation script developed to exploit the CVE-2023-4966 bleed citrix information disclosure vulnerability https://github.com/sanjai-AK47/CVE-2023-4966 POC Details
9 None https://github.com/fdevsectest/CVE-2023-4966 POC Details
10 Scripts to get infos https://github.com/s-bt/CVE-2023-4966 POC Details
11 Programm to exploit a range of ip adresses https://github.com/byte4RR4Y/CVE-2023-4966 POC Details
12 Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation. https://github.com/jmussmann/cve-2023-4966-iocs POC Details
13 Simulates CVE-2023-4966 Citrix Bleed overread bug https://github.com/morganwdavis/overread POC Details
14 Proof Of Concept for te NetScaler Vuln https://github.com/senpaisamp/Netscaler-CVE-2023-4966-POC POC Details
15 An Exploitation script developed to exploit the CVE-2023-4966 bleed citrix information disclosure vulnerability https://github.com/RevoltSecurities/CVE-2023-4966 POC Details
16 None https://github.com/LucasOneZ/CVE-2023-4966 POC Details
17 CVE-2023-4966-exploit https://github.com/akshthejo/CVE-2023-4966-exploit POC Details
18 The vulnerability would enable an attacker to remotely obtain sensitive information from a NetScaler appliance configured as a Gateway or AAA virtual server via a very commonly connected Web interface, and without requiring authentication. This bug is nearly identical to the Citrix Bleed vulnerability (CVE-2023-4966), except it is less likely to return highly sensitive information to an attacker. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/citrix/citrix-oob-memory-read.yaml POC Details
19 Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA ?virtual?server. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4966.yaml POC Details
20 None https://github.com/Threekiii/Awesome-POC/blob/master/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/Citrix%20NetScaler%20ADC%20&%20Gateway%20%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E%20CVE-2023-4966.md POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-4966

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2023-4966 (1)

Other References for CVE-2023-4966 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-4966

No comments yet


Leave a comment