Lucene search

K
citrixCitrixCTX579459
HistoryOct 10, 2023 - 12:07 p.m.

NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2023-4966 and CVE-2023-4967

2023-10-1012:07:11
support.citrix.com
47
netscaler
adc
gateway
vulnerabilities
buffer-related
citrix
customer-managed
versions

9.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

0.971 High

EPSS

Percentile

99.8%

Multiple vulnerabilities have been discovered in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).

Affected Versions:

The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities:

  • NetScaler ADC and NetScaler Gateway14.1before14.1-8.50
  • NetScaler ADC and NetScaler Gateway13.1before13.1-49.15
  • NetScaler ADC and NetScaler Gateway13.0before 13.0-92.19
  • NetScaler ADC 13.1-FIPS before 13.1-37.164
  • NetScaler ADC 12.1-FIPS before 12.1-55.300
  • NetScaler ADC 12.1-NDcPP before 12.1-55.300

Note: NetScaler ADC and NetScaler Gateway version 12.1 is now End-of-Life (EOL) and is vulnerable.

This bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway products. Customers using Citrix-managed cloud services or Citrix-managed Adaptive Authentication do not need to take any action.

Summary:

NetScaler ADC and NetScaler Gateway contain unauthenticated buffer-related vulnerabilities mentioned below

Affected configurations

Vulners
Node
citrixnetscalerRange14.1
OR
citrixnetscalerRange8.50
OR
citrixnetscaler_gatewayRange14.1
OR
citrixnetscaler_gatewayRange8.50
OR
citrixnetscalerRange13.1
OR
citrixnetscalerRange49.15
OR
citrixnetscalerRange14.0.0
OR
citrixnetscalerRange15.0.0
OR
citrixnetscalerRange16.0.0
OR
citrixnetscalerRange17.0.0
OR
citrixnetscalerRange18.0.0
OR
citrixnetscalerRange19.0.0
OR
citrixnetscalerRange20.0.0
OR
citrixnetscalerRange21.0.0
OR
citrixnetscalerRange22.0.0
OR
citrixnetscalerRange23.0.0
OR
citrixnetscalerRange24.0.0
OR
citrixnetscalerRange25.0.0
OR
citrixnetscalerRange26.0.0
OR
citrixnetscalerRange27.0.0
OR
citrixnetscalerRange28.0.0
OR
citrixnetscalerRange29.0.0
OR
citrixnetscalerRange30.0.0
OR
citrixnetscalerRange31.0.0
OR
citrixnetscalerRange32.0.0
OR
citrixnetscalerRange33.0.0
OR
citrixnetscalerRange34.0.0
OR
citrixnetscalerRange35.0.0
OR
citrixnetscalerRange36.0.0
OR
citrixnetscalerRange37.0.0
OR
citrixnetscalerRange38.0.0
OR
citrixnetscalerRange39.0.0
OR
citrixnetscalerRange40.0.0
OR
citrixnetscalerRange41.0.0
OR
citrixnetscalerRange42.0.0
OR
citrixnetscalerRange43.0.0
OR
citrixnetscalerRange44.0.0
OR
citrixnetscalerRange45.0.0
OR
citrixnetscalerRange46.0.0
OR
citrixnetscalerRange47.0.0
OR
citrixnetscalerRange48.0.0
OR
citrixnetscaler_gatewayRange13.1
OR
citrixnetscaler_gatewayRange49.15
OR
citrixnetscaler_gatewayRange14.0.0
OR
citrixnetscaler_gatewayRange15.0.0
OR
citrixnetscaler_gatewayRange16.0.0
OR
citrixnetscaler_gatewayRange17.0.0
OR
citrixnetscaler_gatewayRange18.0.0
OR
citrixnetscaler_gatewayRange19.0.0
OR
citrixnetscaler_gatewayRange20.0.0
OR
citrixnetscaler_gatewayRange21.0.0
OR
citrixnetscaler_gatewayRange22.0.0
OR
citrixnetscaler_gatewayRange23.0.0
OR
citrixnetscaler_gatewayRange24.0.0
OR
citrixnetscaler_gatewayRange25.0.0
OR
citrixnetscaler_gatewayRange26.0.0
OR
citrixnetscaler_gatewayRange27.0.0
OR
citrixnetscaler_gatewayRange28.0.0
OR
citrixnetscaler_gatewayRange29.0.0
OR
citrixnetscaler_gatewayRange30.0.0
OR
citrixnetscaler_gatewayRange31.0.0
OR
citrixnetscaler_gatewayRange32.0.0
OR
citrixnetscaler_gatewayRange33.0.0
OR
citrixnetscaler_gatewayRange34.0.0
OR
citrixnetscaler_gatewayRange35.0.0
OR
citrixnetscaler_gatewayRange36.0.0
OR
citrixnetscaler_gatewayRange37.0.0
OR
citrixnetscaler_gatewayRange38.0.0
OR
citrixnetscaler_gatewayRange39.0.0
OR
citrixnetscaler_gatewayRange40.0.0
OR
citrixnetscaler_gatewayRange41.0.0
OR
citrixnetscaler_gatewayRange42.0.0
OR
citrixnetscaler_gatewayRange43.0.0
OR
citrixnetscaler_gatewayRange44.0.0
OR
citrixnetscaler_gatewayRange45.0.0
OR
citrixnetscaler_gatewayRange46.0.0
OR
citrixnetscaler_gatewayRange47.0.0
OR
citrixnetscaler_gatewayRange48.0.0
OR
citrixnetscalerRange13.0
OR
citrixnetscalerRange92.19
OR
citrixnetscalerRange14.0.0
OR
citrixnetscalerRange15.0.0
OR
citrixnetscalerRange16.0.0
OR
citrixnetscalerRange17.0.0
OR
citrixnetscalerRange18.0.0
OR
citrixnetscalerRange19.0.0
OR
citrixnetscalerRange20.0.0
OR
citrixnetscalerRange21.0.0
OR
citrixnetscalerRange22.0.0
OR
citrixnetscalerRange23.0.0
OR
citrixnetscalerRange24.0.0
OR
citrixnetscalerRange25.0.0
OR
citrixnetscalerRange26.0.0
OR
citrixnetscalerRange27.0.0
OR
citrixnetscalerRange28.0.0
OR
citrixnetscalerRange29.0.0
OR
citrixnetscalerRange30.0.0
OR
citrixnetscalerRange31.0.0
OR
citrixnetscalerRange32.0.0
OR
citrixnetscalerRange33.0.0
OR
citrixnetscalerRange34.0.0
OR
citrixnetscalerRange35.0.0
OR
citrixnetscalerRange36.0.0
OR
citrixnetscalerRange37.0.0
OR
citrixnetscalerRange38.0.0
OR
citrixnetscalerRange39.0.0
OR
citrixnetscalerRange40.0.0
OR
citrixnetscalerRange41.0.0
OR
citrixnetscalerRange42.0.0
OR
citrixnetscalerRange43.0.0
OR
citrixnetscalerRange44.0.0
OR
citrixnetscalerRange45.0.0
OR
citrixnetscalerRange46.0.0
OR
citrixnetscalerRange47.0.0
OR
citrixnetscalerRange48.0.0
OR
citrixnetscalerRange49.0.0
OR
citrixnetscalerRange50.0.0
OR
citrixnetscalerRange51.0.0
OR
citrixnetscalerRange52.0.0
OR
citrixnetscalerRange53.0.0
OR
citrixnetscalerRange54.0.0
OR
citrixnetscalerRange55.0.0
OR
citrixnetscalerRange56.0.0
OR
citrixnetscalerRange57.0.0
OR
citrixnetscalerRange58.0.0
OR
citrixnetscalerRange59.0.0
OR
citrixnetscalerRange60.0.0
OR
citrixnetscalerRange61.0.0
OR
citrixnetscalerRange62.0.0
OR
citrixnetscalerRange63.0.0
OR
citrixnetscalerRange64.0.0
OR
citrixnetscalerRange65.0.0
OR
citrixnetscalerRange66.0.0
OR
citrixnetscalerRange67.0.0
OR
citrixnetscalerRange68.0.0
OR
citrixnetscalerRange69.0.0
OR
citrixnetscalerRange70.0.0
OR
citrixnetscalerRange71.0.0
OR
citrixnetscalerRange72.0.0
OR
citrixnetscalerRange73.0.0
OR
citrixnetscalerRange74.0.0
OR
citrixnetscalerRange75.0.0
OR
citrixnetscalerRange76.0.0
OR
citrixnetscalerRange77.0.0
OR
citrixnetscalerRange78.0.0
OR
citrixnetscalerRange79.0.0
OR
citrixnetscalerRange80.0.0
OR
citrixnetscalerRange81.0.0
OR
citrixnetscalerRange82.0.0
OR
citrixnetscalerRange83.0.0
OR
citrixnetscalerRange84.0.0
OR
citrixnetscalerRange85.0.0
OR
citrixnetscalerRange86.0.0
OR
citrixnetscalerRange87.0.0
OR
citrixnetscalerRange88.0.0
OR
citrixnetscalerRange89.0.0
OR
citrixnetscalerRange90.0.0
OR
citrixnetscalerRange91.0.0
OR
citrixnetscaler_gatewayRange13.0
OR
citrixnetscaler_gatewayRange92.19
OR
citrixnetscaler_gatewayRange14.0.0
OR
citrixnetscaler_gatewayRange15.0.0
OR
citrixnetscaler_gatewayRange16.0.0
OR
citrixnetscaler_gatewayRange17.0.0
OR
citrixnetscaler_gatewayRange18.0.0
OR
citrixnetscaler_gatewayRange19.0.0
OR
citrixnetscaler_gatewayRange20.0.0
OR
citrixnetscaler_gatewayRange21.0.0
OR
citrixnetscaler_gatewayRange22.0.0
OR
citrixnetscaler_gatewayRange23.0.0
OR
citrixnetscaler_gatewayRange24.0.0
OR
citrixnetscaler_gatewayRange25.0.0
OR
citrixnetscaler_gatewayRange26.0.0
OR
citrixnetscaler_gatewayRange27.0.0
OR
citrixnetscaler_gatewayRange28.0.0
OR
citrixnetscaler_gatewayRange29.0.0
OR
citrixnetscaler_gatewayRange30.0.0
OR
citrixnetscaler_gatewayRange31.0.0
OR
citrixnetscaler_gatewayRange32.0.0
OR
citrixnetscaler_gatewayRange33.0.0
OR
citrixnetscaler_gatewayRange34.0.0
OR
citrixnetscaler_gatewayRange35.0.0
OR
citrixnetscaler_gatewayRange36.0.0
OR
citrixnetscaler_gatewayRange37.0.0
OR
citrixnetscaler_gatewayRange38.0.0
OR
citrixnetscaler_gatewayRange39.0.0
OR
citrixnetscaler_gatewayRange40.0.0
OR
citrixnetscaler_gatewayRange41.0.0
OR
citrixnetscaler_gatewayRange42.0.0
OR
citrixnetscaler_gatewayRange43.0.0
OR
citrixnetscaler_gatewayRange44.0.0
OR
citrixnetscaler_gatewayRange45.0.0
OR
citrixnetscaler_gatewayRange46.0.0
OR
citrixnetscaler_gatewayRange47.0.0
OR
citrixnetscaler_gatewayRange48.0.0
OR
citrixnetscaler_gatewayRange49.0.0
OR
citrixnetscaler_gatewayRange50.0.0
OR
citrixnetscaler_gatewayRange51.0.0
OR
citrixnetscaler_gatewayRange52.0.0
OR
citrixnetscaler_gatewayRange53.0.0
OR
citrixnetscaler_gatewayRange54.0.0
OR
citrixnetscaler_gatewayRange55.0.0
OR
citrixnetscaler_gatewayRange56.0.0
OR
citrixnetscaler_gatewayRange57.0.0
OR
citrixnetscaler_gatewayRange58.0.0
OR
citrixnetscaler_gatewayRange59.0.0
OR
citrixnetscaler_gatewayRange60.0.0
OR
citrixnetscaler_gatewayRange61.0.0
OR
citrixnetscaler_gatewayRange62.0.0
OR
citrixnetscaler_gatewayRange63.0.0
OR
citrixnetscaler_gatewayRange64.0.0
OR
citrixnetscaler_gatewayRange65.0.0
OR
citrixnetscaler_gatewayRange66.0.0
OR
citrixnetscaler_gatewayRange67.0.0
OR
citrixnetscaler_gatewayRange68.0.0
OR
citrixnetscaler_gatewayRange69.0.0
OR
citrixnetscaler_gatewayRange70.0.0
OR
citrixnetscaler_gatewayRange71.0.0
OR
citrixnetscaler_gatewayRange72.0.0
OR
citrixnetscaler_gatewayRange73.0.0
OR
citrixnetscaler_gatewayRange74.0.0
OR
citrixnetscaler_gatewayRange75.0.0
OR
citrixnetscaler_gatewayRange76.0.0
OR
citrixnetscaler_gatewayRange77.0.0
OR
citrixnetscaler_gatewayRange78.0.0
OR
citrixnetscaler_gatewayRange79.0.0
OR
citrixnetscaler_gatewayRange80.0.0
OR
citrixnetscaler_gatewayRange81.0.0
OR
citrixnetscaler_gatewayRange82.0.0
OR
citrixnetscaler_gatewayRange83.0.0
OR
citrixnetscaler_gatewayRange84.0.0
OR
citrixnetscaler_gatewayRange85.0.0
OR
citrixnetscaler_gatewayRange86.0.0
OR
citrixnetscaler_gatewayRange87.0.0
OR
citrixnetscaler_gatewayRange88.0.0
OR
citrixnetscaler_gatewayRange89.0.0
OR
citrixnetscaler_gatewayRange90.0.0
OR
citrixnetscaler_gatewayRange91.0.0
OR
citrixnetscalerRange13.1
OR
citrixnetscalerRange12.1
OR
citrixnetscalerRange12.1

9.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

0.971 High

EPSS

Percentile

99.8%