CVE-2023-4967: Denial of service
Published Oct 27, 2023
·Updated
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Affected Software
9 affected components
Citrix NetScaler Application Delivery Controller>=13.0<13.0-92.19
Citrix NetScaler Application Delivery Controller>=13.1<13.1-49.15
Citrix NetScaler Application Delivery Controller>=14.1<14.1-8.50
Citrix NetScaler Gateway>=13.0<13.0-92.19
Citrix NetScaler Gateway>=13.1<13.1-49.15
Citrix NetScaler Gateway>=14.1<14.1-8.50
Citrix NetScaler Application Delivery Controller>=12.1<=12.1-55.300
Citrix NetScaler Application Delivery Controller>=12.1<=12.1-55.300
Citrix NetScaler Application Delivery Controller>=13.1<=13.1-37.164
Event History
Oct 27, 2023
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4967?
CVE-2023-4967 is a vulnerability that allows for Denial of Service attacks in NetScaler ADC and NetScaler Gateway.
2
How does CVE-2023-4967 affect Citrix NetScaler Application Delivery Controller?
CVE-2023-4967 affects Citrix NetScaler Application Delivery Controller versions between 13.0-92.19 and 14.1-8.50.
3
How does CVE-2023-4967 affect Citrix NetScaler Gateway?
CVE-2023-4967 affects Citrix NetScaler Gateway versions between 13.0-92.19 and 14.1-8.50.
4
What is the severity of CVE-2023-4967?
CVE-2023-4967 has a severity rating of 8.2 (high).
5
How can I fix CVE-2023-4967?
To fix CVE-2023-4967, update your Citrix NetScaler ADC or NetScaler Gateway to a version that is not affected by the vulnerability.