#VU81927 Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2023-4967
Published: October 11, 2023
Citrix Netscaler ADC
Citrix NetScaler Gateway
Citrix
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote non-authenticated attacker can send specially crafted data
to the device, trigger memory corruption and perform a denial of service (DoS) attack.
Successful exploitation of this vulnerability requires that the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as AAAvirtualserver.
Remediation
Install updates from vendor's website.
For FIPS releases install the following versions:
- NetScaler ADC 13.1-FIPS version 13.1-37.164
- NetScaler ADC 12.1-FIPS version 12.1-55.300
- NetScaler ADC 12.1-NDcPP version 12.1-55.300