Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway have exposed sensitive information and a denial of service attack.
A malicious cyber actor can exploit one of these vulnerabilities to gain control of an affected machine. Citrix has published security upgrades to address the vulnerabilities impacting several products.
Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware
With a CVSS score of 9.4, the vulnerability designated as CVE-2023–4966 is considered highly severe. Without high-level access, user involvement, or tedious processes, the weakness may be remotely exploited.
The appliance must be set up as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server to be exposed to attacks.
According to the security bulletin, this vulnerability results in “Sensitive information disclosure.”
The second vulnerability reported is CVE-2023-4967, a high-severity issue with a CVSS score of 8.2, allowing for a ‘Denial of Service attack’ on vulnerable devices.
The vulnerabilities impact the following supported versions of NetScaler ADC and NetScaler Gateway:
It is noted that NetScaler ADC and NetScaler Gateway version 12.1 are now End-of-Life (EOL) and are vulnerable.
NetScaler ADC and NetScaler Gateway version 12.1 are now End-of-Life (EOL). Customers are advised to update one of the supported versions to fix the vulnerabilities.
“Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions of NetScaler ADC and NetScaler Gateway as soon as possible,” reads Citrix’s security bulletin.
Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.
Sophos Managed Detection and Response (MDR) in September 2024, the notorious Lumma Stealer malware has…
Cybercriminals have unleashed a new malware campaign using fake AI video generation platforms as a…
The North Korean state-sponsored Advanced Persistent Threat (APT) group Kimsuky, also known as “Black Banshee,”…
The North Korean state-sponsored hacking group APT37, also known as ScarCruft, launched a spear phishing…
IPFire, the powerful open-source firewall, has unveiled its latest release, IPFire 2.29 – Core Update…
Distributed Denial of Service (DDoS) attacks, once seen as crude tools for disruption wielded by…