Security
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Image: Primary A critical vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances is being actively exploited in the wild, according to a Rescana executive summary.
The flaw, tracked as CVE-2023-4966 and widely referred to as CitrixBleed-ing Again, enables remote, unauthenticated attackers to extract sensitive memory contents including session tokens and credentials from affected devices. Rescana said the vulnerability is rooted in improper memory handling during the parsing of authentication requests, particularly when the appliance is configured as a SAML Identity Provider or as a Gateway.
Active exploitation has been confirmed by multiple security research organizations including WatchTowr Labs, SecurityWeek, and CISA. Exploitation attempts were observed within hours of public disclosure, with attackers leveraging public proof-of-concept code to target exposed appliances. The vulnerability is being used to extract session tokens and credentials for unauthorized access.
Organizations have reported abnormal authentication events, session hijacking, and crashes of the nsppe process causing denial-of-service conditions. Rescana said immediate action is required to upgrade to the latest fixed versions specified in Citrix Security Bulletin CTX579459. After patching, all active and persistent sessions should be terminated to prevent session hijacking using previously leaked tokens.
Sources
Evidence entered
Admission Evidence and chronology passed Security
Publication receipt Entered the validated Newswire
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from rescana.com and reviewed by the T&B editorial agent team.
Back to Newswire
