VYPR
Critical severity9.4CISA KEVNVD Advisory· Published Oct 10, 2023· Updated Jul 31, 2026

CVE-2023-4966

CVE-2023-4966

Description

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*+ 2 more
    • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*range: >=13.0,<13.0-92.19
    • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*range: >=12.1,<12.1-55.300
    • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*range: >=12.1,<12.1-55.300
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*range: >=13.0,<13.0-92.19
    • (no CPE)range: 14.1
  • Citrix Systems/Netscalerllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 14.1

Patches

Vulnerability mechanics

References

3

News mentions

6