S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-4966 Scanner

Targets the Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server endpoints to leak sensitive data like usernames and passwords.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-4966
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
NetScaler ADCby Citrix
AFFECTED< 8.50SAFE ✓≥ 8.50
NetScaler Gatewayby Citrix
AFFECTED< 8.50SAFE ✓≥ 8.50
Updated Aug 22, 2026View on NVD →
Detail

Citrix NetScaler ADC and NetScaler Gateway are critical networking tools used for application delivery and secure remote access. NetScaler ADC optimizes web and mobile app performance, while NetScaler Gateway provides VPN and proxy services for remote workers. These products are widely deployed in enterprise environments to ensure reliable and secure connectivity.

CVE-2023-4966 is an information disclosure vulnerability that arises due to improper handling of sensitive data in specific virtual server configurations. When the Gateway or AAA virtual server is misconfigured, it can inadvertently expose confidential information such as usernames and passwords. This flaw stems from insufficient access controls or data sanitization in the affected components.

Technically, the vulnerability is triggered through crafted requests to the Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server endpoints. Attackers can exploit this by sending specially formatted queries that cause the server to return sensitive data in the response. The issue lies in how these endpoints process and output authentication-related information without proper validation.

If exploited, this vulnerability can lead to unauthorized access to corporate networks and sensitive data. Attackers can use disclosed credentials to bypass authentication, infiltrate systems, and perform data exfiltration or lateral movement. The impact is severe, potentially compromising entire network infrastructures and causing significant operational and reputational damage.

Solution Advice
  • Apply the latest security patches from Citrix for NetScaler ADC and Gateway to address CVE-2023-4966.
  • Audit all Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) and AAA virtual server configurations for misconfigurations.
  • Restrict access to NetScaler management interfaces to trusted IP addresses only.
  • Implement strong authentication mechanisms, such as multi-factor authentication (MFA), for all remote access users.
  • Monitor NetScaler logs for unusual access patterns or repeated failed login attempts.
  • Disable unnecessary virtual server features that are not required for your environment.
  • Conduct regular vulnerability scans using tools like S4E to detect and remediate similar issues promptly.
  • Enforce the principle of least privilege for all user accounts and service accounts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-4966 NetScaler Info Disclosure Scanner | S4E Free Check S4E