CVE-2023-4966: Citrix Bleed
A buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that leaks session tokens from device memory. An unauthenticated attacker who captures a valid session token can hijack an authenticated session, bypassing both MFA and password requirements, and it was widely exploited by ransomware groups in late 2023.
View the authoritative record on NVD ↗Affected software
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50
- 13.1 before 13.1-49.15
- 13.0 before 13.0-92.19
- NetScaler ADC 13.1-FIPS before 13.1-37.164
- NetScaler ADC 12.1-FIPS before 12.1-55.300
How it's exploited
Send a crafted HTTP request to a NetScaler endpoint configured as a Gateway or AAA virtual server that overflows a buffer, causing the device to leak adjacent memory containing valid session tokens back to the attacker.
Severity
CVE-2023-4966 carries a CVSS 3.1 base score of 9.4, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2023-4966 is categorized under CWE-119, CWE-200, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Apply the Citrix-published fixed builds, then terminate all active ICA and PCoIP sessions, since previously issued session tokens remain valid and exploitable until explicitly killed.
Frequently asked questions
What is CVE-2023-4966?
A buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that leaks session tokens from device memory. An unauthenticated attacker who captures a valid session token can hijack an authenticated session, bypassing both MFA and password requirements, and it was widely exploited by ransomware groups in late 2023.
How severe is CVE-2023-4966?
CVE-2023-4966 has a CVSS 3.1 base score of 9.4 out of 10, rated Critical.
What software is affected by CVE-2023-4966?
CVE-2023-4966 affects NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50; 13.1 before 13.1-49.15; 13.0 before 13.0-92.19; NetScaler ADC 13.1-FIPS before 13.1-37.164; NetScaler ADC 12.1-FIPS before 12.1-55.300.
How do you fix CVE-2023-4966?
Apply the Citrix-published fixed builds, then terminate all active ICA and PCoIP sessions, since previously issued session tokens remain valid and exploitable until explicitly killed.
Where is the authoritative record for CVE-2023-4966?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2023-4966 at https://nvd.nist.gov/vuln/detail/CVE-2023-4966, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest