8.2

CVE-2023-4967

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

Data is provided by the National Vulnerability Database (NVD)
CitrixNetscaler Application Delivery Controller Version >= 13.0 < 13.0-92.19
CitrixNetscaler Application Delivery Controller Version >= 13.1 < 13.1-49.15
CitrixNetscaler Application Delivery Controller Version >= 14.1 < 14.1-8.50
CitrixNetScaler Gateway Version >= 13.0 < 13.0-92.19
CitrixNetScaler Gateway Version >= 13.1 < 13.1-49.15
CitrixNetScaler Gateway Version >= 14.1 < 14.1-8.50
CitrixNetscaler Application Delivery Controller SwEditionfips Version >= 12.1 <= 12.1-55.300
CitrixNetscaler Application Delivery Controller SwEditionndcpp Version >= 12.1 <= 12.1-55.300
CitrixNetscaler Application Delivery Controller SwEditionfips Version >= 13.1 <= 13.1-37.164
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.44% 0.623
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
secure@citrix.com 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.