Critical Citrix NetScaler Flaw Exploited to Target from Government, Tech Firms
Oct 18, 2023
Enterprise Security / Vulnerability
 Citrix is warning of exploitation of a recently disclosed critical security flaw in NetScaler ADC and Gateway appliances that could result in exposure of sensitive information.  Tracked as  CVE-2023-4966  (CVSS score: 9.4), the vulnerability impacts the following supported versions -   NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50  NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.15  NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.19  NetScaler ADC and NetScaler Gateway 12.1 (currently end-of-life)  NetScaler ADC 13.1-FIPS before 13.1-37.164  NetScaler ADC 12.1-FIPS before 12.1-55.300, and  NetScaler ADC 12.1-NDcPP before 12.1-55.300   However, for exploitation to occur, it requires the device to be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or authorization and accounting (AAA) virtual server.  While patches for the flaw were released on October 10, 2023, Citrix has now revised the advisory to note that "exploits of CV...