Recently, two critical security vulnerabilities were discovered, that affect Citrix NetScaler ADC and NetScaler Gateway products. The vulnerabilities, CVE-2023-4966 and CVE-2023-4967, cause sensitive information disclosure and denial of service to the affected devices. Exploits of CVE-2023-4966 on unmitigated appliances have been observed in the wild.
Citrix NetScaler is a product that provides application delivery and load balancing services.
CVE-2023-4966 and CVE-2023-4967 are two critical security vulnerabilities discovered in October 2023, that affect Citrix NetScaler ADC and NetScaler Gateway products as mentioned above.
CVE-2023-4966, allows attackers to access sensitive information on vulnerable devices. Specifically, when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, it can lead to sensitive information disclosure. CVE-2023-4966 has a CVSS score of 9.4 out of 10.
CVE-2023-4967, allows the attacker to cause denial of service. Similarly to CVE-2023-4966, this happens when the appliance is configured as a Gateway or AAA virtual server. CVE-2023-4967 has a CVSS score of 8.2 out of 10.
Both of the vulnerability scores indicate high severity and impact.
Successful exploitation could result in the ability to hijack existing authenticated sessions, therefore bypassing strong authentication requirements. This could result in further access based upon the permissions and scope of access that the session was permitted. A threat actor could utilize this method to gather additional credentials, laterally pivot, and gain access to additional resources within an environment.
The following versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities:
NetScaler ADC and NetScaler Gateway version 12.1 is now End-of-Life (EOL) and is vulnerable.
It is important that all users of the above products follow the recommendations to prevent exploitation:
Customers using NetScaler ADC and NetScaler Gateway version 12.1 are recommended to upgrade their appliances to one of the above supported versions.
NetScaler ADC and NetScaler Gateway appliances that are not configured as a gateway or as an AAA virtual server and products such as NetScaler Application Delivery Management (ADM) and Citrix SD-WAN are not affected.
https://thehackernews.com/2023/10/critical-citrix-netscaler-flaw.html
https://nvd.nist.gov/vuln/detail/CVE-2023-4966