CVE-2023-4966

CVE Published 2023-10-10
Related CWE(s) CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Related Vendor(s) citrix
Related Product(s) netscaler_gateway, netscaler_application_delivery_controller
Exploitation Reported (CISA KEV) 2023-10-18
CVSS 3 Base Score 9.4 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA ?virtual?server. 

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2023-4966

Report

GOLD IONIC DEPLOYS INC RANSOMWARE

This blog post from Secureworks describes the intrusion set they track as GOLD IONIC, also known as INC Ransom Group. The post outlines GOLD IONIC ...

Associated CAPEC Patterns

References