PT-2023-5875 · Citrix+1 · Citrix Netscaler Adc+2

CVE-2023-4966

·

Published

2023-10-10

·

Updated

2026-09-04

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions NetScaler ADC (affected versions not specified) NetScaler Gateway (affected versions not specified)
Description A buffer overflow issue exists in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. This flaw allows a remote attacker to cause a disclosure of sensitive information, potentially impacting the confidentiality, integrity, and availability of protected data. A real-world incident involved Comcast Cable Communications (Xfinity), where attackers accessed servers to steal customer usernames, hashed passwords, contact details, social security numbers, and security questions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06568
CVE-2023-4966

Affected Products

Citrix Netscaler Adc
Citrix Netscaler Gateway
Comcast Xfinity