CVE-2023-4967: Sensitive information disclosure in Citrix NetScaler ADC/Gateway, 9.4 rating❗️
The vulnerability emerges from the return value of the snprintf function, which can lead to a buffer over-read if exploited. By this, the session token can be intercepted. Also, PoC is available now.
Search at Netlas.io:
👉🏻 Link: https://nt.ls/5g7Md
👉🏻 Dork: http.title:"Netscaler Gateway" OR http.headers.x_powered_by:"Citrix ADC (formerly NetScaler)"
Read about PoC: https://www.bleepingcomputer.com/news/security/citrix-bleed-exploit-lets-hackers-hijack-netscaler-accounts/
Vendor's advisory: https://support.citrix.com/article/CTX579459
Post #112
779

- 🔥 4
- 👾 2