EXPOSURES › CVE-2023-4966
CVE-2023-4966
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCitrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks.
The buffer overflow in Citrix NetScaler ADC and Gateway allowed sensitive information disclosure, which was actively exploited by ransomware actors. DIB organizations must ensure these systems are patched immediately, as unpatched instances are high-value targets for supply-chain and ransomware attacks. This failure highlights the severe risk of relying on known, unpatched vulnerabilities in critical network infrastructure.
Shame score — A critical, actively exploited vulnerability in widely deployed network infrastructure that was linked to ransomware, demonstrating severe negligence in patch management and supply-chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |