PT-2023-5875 · Citrix+1 · Citrix Netscaler Adc+2
CVE-2023-4966
·
Published
2023-10-10
·
Updated
2026-09-04
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
NetScaler ADC (affected versions not specified)
NetScaler Gateway (affected versions not specified)
Description
A buffer overflow issue exists in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. This flaw allows a remote attacker to cause a disclosure of sensitive information, potentially impacting the confidentiality, integrity, and availability of protected data. A real-world incident involved Comcast Cable Communications (Xfinity), where attackers accessed servers to steal customer usernames, hashed passwords, contact details, social security numbers, and security questions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Netscaler Adc
Citrix Netscaler Gateway
Comcast Xfinity