CVE-2023-3466 — Improper Input Validation in Citrix ADC
Severity
8.3HIGHVulnCheck
No vectorEPSS
1.2%
top 21.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
Latest updateFeb 26
Description
Citrix NetScaler ADC and NetScaler Gateway Improper Input Validation
Reflected Cross-Site Scripting (XSS)
Affected: Citrix NetScaler ADC and NetScaler Gateway
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.sentinelone.com/resources/watchtower-end-of-year-report-2023/; https://www.cisa.gov/sites/default/files/2024-11/aa24-317a-2023-top-routinely-exp…
Affected Packages5 packages
🔴Vulnerability Details
1📋Vendor Advisories
1Citrix▶
Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-3467↗2023-07-18
🕵️Threat Intelligence
15Greynoiseio▶
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs↗2025-02-26
Trendmicro▶
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella↗2024-11-19
Trendmicro▶
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella↗2024-11-19