Toutes les vulnérabilités
CRITICALInfraexploited in the wildransomware

CVE-2023-4966

Citrix NetScaler · Citrix NetScaler ADC and NetScaler Gateway

Résumé

A sensitive-information-disclosure flaw (memory buffer over-read) in NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server. A specially crafted request leaks memory contents including valid session tokens, letting an unauthenticated attacker hijack authenticated sessions and bypass passwords and MFA. Mandiant confirmed zero-day exploitation since late August 2023, about six weeks before the patch, followed by mass exploitation. LockBit 3.0 ransomware affiliates and multiple nation-state groups used it for initial access. NVD scores it 7.5 High while Citrix rates it 9.4 Critical.

Références

Vulnérabilités liées

Tout Infra →