CVE-2023-4966
Unauthenticated sensitive information disclosure
- Published
- Oct 10, 2023
- Updated
- Jul 31, 2026
- Assigning CNA
- Citrix
- Evidence observed
- Oct 18, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Sources
11- CVE-2023-4966Exploit
CVE-2023-4966 - NetScaler ADC and NetScaler Gateway Memory Leak Exploit
- citrix_cve-2023-4966Scanner
Parallelized exploit scanner for Citrix CVE-2023-4966 with file-based target handling, enabling rapid vulnerability verification across multiple hosts.
- CVE-2023-4966-POCExploit
Proof Of Concept for te NetScaler Vuln
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.