Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Loading...
Loading...
Score elevated to 9.4 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-10-18), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.4 retained for reference. Confidence: HIGH.
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
October 10, 2023
October 24, 2025
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4966MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Metasploit module) (7 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Simulates CVE-2023-4966 Citrix Bleed overread bug
Open source ↗An Exploitation script developed to exploit the CVE-2023-4966 bleed citrix information disclosure vulnerability
Open source ↗Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation
Open source ↗Citrix CVE-2023-4966 from assetnote modified for parallel and file handling
Open source ↗Assetnote PoC for session-token extraction from vulnerable NetScaler appliances.
Open source ↗Proof Of Concept for te NetScaler Vuln
Open source ↗Citrix ADC (NetScaler) Bleed Scanner
Open source ↗Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Open source ↗Citrix Bleed - Leaking Session Tokens
Open source ↗This CVE was central to one or more publicly-documented breaches. Each card links to authoritative reporting at the time of the incident.
NetScaler ADC/Gateway buffer over-read leaked session tokens, letting attackers bypass MFA. Exploited by ransomware groups (LockBit, Medusa) against Boeing, ICBC, and Comcast within weeks of disclosure.
Source: BleepingComputerSee which npm, PyPI, Go, and Maven packages are affected by CVE-2023-4966
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
CWE-119