CVE-2023-4967Improper Restriction of Operations within the Bounds of a Memory Buffer in Software Group Netscaler ADC

Severity
7.5HIGHNVD
VulnCheck8.2
EPSS
0.4%
top 36.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateDec 6

Description

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

NVDcitrix/netscaler_gateway13.013.0-92.19+2
CVEListV5cloud_software_group/netscaler_gateway14.18.50+2
CVEListV5cloud_software_group/netscaler_adc14.18.50+5

🔴Vulnerability Details

2
GHSA
GHSA-wj66-97v8-j738: Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual2023-10-27
VulnCheck
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer2023

📋Vendor Advisories

1
Citrix
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2023-4966 and CVE-2023-49672023-10-17

🕵️Threat Intelligence

8
Tenable
CVE-2023-4966 (CitrixBleed): Invalidate Active or Persistent Sessions To Prevent Further Compromise2023-12-06
Tenable
Frequently Asked Questions for CitrixBleed (CVE-2023-4966)2023-11-20
Wiz
Crying Out Cloud - November Newsletter | Wiz2023-11-01
Unit42
Threat Brief: Citrix Bleed CVE-2023-49662023-11-01
Unit42
Threat Brief: Citrix Bleed CVE-2023-49662023-11-01