---
id: CVE-2023-4966
title: "Sensitive information disclosure\_in NetScaler ADC and NetScaler Gateway when configured as a\_Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)\_or\_AAA  virtual server."
summary: "Sensitive information disclosure\_in NetScaler ADC and NetScaler Gateway when configured as a\_Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)\_or\_AAA  virtual server."
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-119
vendor: citrix
product: netscaler_application_delivery_controller
affected:
  - 'netscaler_application_delivery_controller >= 12.1, < 12.1-55.300'
  - 'netscaler_application_delivery_controller >= 13.0, < 13.0-92.19'
  - 'netscaler_application_delivery_controller >= 13.1, < 13.1-37.164'
  - 'netscaler_application_delivery_controller >= 13.1, < 13.1-49.15'
  - 'netscaler_application_delivery_controller >= 14.1, < 14.1-8.50'
  - 'netscaler_gateway >= 13.0, < 13.0-92.19'
  - 'netscaler_gateway >= 13.1, < 13.1-49.15'
  - 'netscaler_gateway >= 14.1, < 14.1-8.50'
patched:
  - netscaler_application_delivery_controller 14.1-8.50
  - netscaler_gateway 14.1-8.50
published: '2023-10-10'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4966'
references:
  - url: >-
      http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.html
    label: secure@citrix.com
  - url: 'https://support.citrix.com/article/CTX579459'
    label: secure@citrix.com
  - url: >-
      http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.citrix.com/article/CTX579459'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4966
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99999
epssPercentile: 0.99998
kev: true
kevDateAdded: '2023-10-18'
kevDueDate: '2023-11-08'
kevRansomware: true
exploited: true
ingestedAt: '2026-07-31T04:58:34.420Z'
exploits:
  github: 14
  githubRepos:
    - 'https://github.com/Chocapikk/CVE-2023-4966'
    - 'https://github.com/dinosn/citrix_cve-2023-4966'
    - 'https://github.com/mlynchcogent/CVE-2023-4966-POC'
  metasploit:
    - auxiliary/scanner/http/citrix_bleed_cve_2023_4966
  nuclei:
    - CVE-2023-4966
  checkedAt: '2026-09-08T15:36:49.846Z'
exploitAvailable: true
---

## Overview

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

## Affected

- `netscaler_application_delivery_controller >= 12.1, < 12.1-55.300`
- `netscaler_application_delivery_controller >= 13.0, < 13.0-92.19`
- `netscaler_application_delivery_controller >= 13.1, < 13.1-37.164`
- `netscaler_application_delivery_controller >= 13.1, < 13.1-49.15`
- `netscaler_application_delivery_controller >= 14.1, < 14.1-8.50`
- `netscaler_gateway >= 13.0, < 13.0-92.19`
- `netscaler_gateway >= 13.1, < 13.1-49.15`
- `netscaler_gateway >= 14.1, < 14.1-8.50`

## Remediation

Upgrade past the affected range:

- `netscaler_application_delivery_controller 14.1-8.50`
- `netscaler_gateway 14.1-8.50`
