CVE-2023-4966
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
- Affected products
- Citrix Netscaler Adc, Citrix Netscaler Gateway, Comcast Xfinity
- Citrix Netscaler Application Delivery Controller
- < 12.1-55.300, 13.0-92.19, 13.1-37.164, 13.1-49.15, 14.1-8.50
- Citrix Netscaler Gateway
- < 13.0-92.19, 13.1-49.15, 14.1-8.50
- CVSS 3.1
- 9.4 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-119
- NVD status
- Analyzed
- Published
- 2023-10-10
CVE-2023-4966 at NVD
16 known exploits for CVE-2023-4966
Proof-of-concept code and exploit modules indexed by Sploitus
cve-deep-dives
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Use of Uninitialized Resource in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Citrix ADC (NetScaler) Bleed Scanner
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Citrix ADC (NetScaler) Bleed Scanner
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
CVE-2023-4966