CVE-2023-4966
⚡ CISA KEV🔐 RansomwarePublished: 2023-10-10Modified: 2026-07-31Vendor: CitrixProduct: NetScaler ADC and NetScaler Gateway
9.4
CVSS v3
100.0%
EPSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
⚡ Added to KEV on 2023-10-18 · Federal agencies must remediate by 2023-11-08
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CWE:CWE-119
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules4
Rules tagged with this CVE
| high | CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy | — | — |
| high | CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver | — | — |
| medium | CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy | — | — |
| medium | CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver | — | — |
🛠️ Patch Details1
Affected/fixed versions from threat intel reports
| Citrix NetScaler | source ↗ |
📰 Threat Intel Coverage3
Digest reports mentioning this CVE
📎 References5
↗ http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.html↗ https://support.citrix.com/article/CTX579459↗ http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.html↗ https://support.citrix.com/article/CTX579459↗ https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4966