CVE-2023-4966: Unauthenticated sensitive information disclosure
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Other sources
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
— NVD
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA ?virtual?server.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4966?
CVE-2023-4966 is a buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows for sensitive information disclosure when configured as a Gateway or AAA virtual server.
What software is affected by CVE-2023-4966?
Citrix NetScaler ADC and NetScaler Gateway versions 12.1-55.300 to 14.1-8.50 are affected by CVE-2023-4966.
What is the severity of CVE-2023-4966?
CVE-2023-4966 has a severity rating of 7.5 (Critical).
How can I fix CVE-2023-4966?
Citrix has released security bulletins and patches for CVE-2023-4966. It is recommended to apply the relevant patches or updates provided by Citrix.
Where can I find more information about CVE-2023-4966?
You can find more information about CVE-2023-4966 on the official Citrix support website: https://support.citrix.com/article/CTX579459