• Language chooser
    • USA (English)
    • France (Français)

Citrix Bleed Attack

Released: Nov 02, 2023

Updated: Nov 02, 2023


High Severity

Vulnerability, Attack Type


NetScaler ADC and NetScaler Gateway Vulnerability Actively Exploited

CVE-2023-4966 is being widely exploited, with multiple threat actors, including ransomware groups, targeting internet-accessible NetScaler ADC and Gateway instances. After exploiting CVE-2023-4966, the attackers may engage in network reconnaissance, stealing account credentials and moving laterally via RDP. Learn More »

Common Vulnerabilities and Exposures

CVE-2023-4966

Background

Citrix Netscaler is a network device providing load balancing, firewall and VPN services. NetScaler Gateway usually refers to the VPN and authentication components, whereas ADC refers to the load balancing and traffic management features. CVE-2023-4966 is a sensitive information disclosure vulnerability in NetScaler ADC and NetScaler Gateway . As of October 30, Shadowserver spotted just over 5,000 vulnerable servers on the public internet.

Latest Development

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.


Oct. 10, 2023: Citrix released a security bulletin for a sensitive information disclosure vulnerability (CVE-2023-4966) impacting NetScaler ADC and NetScaler Gateway appliances. https://support.citrix.com/article/CTX579459/

Oct 18, 2023: CISA added CVE-2023-4966 to its known exploited list, KEV catalog.

Oct 25, 2023 AssetNote researchers released a proof-of-concept (PoC) exploit demonstrating how to hijack a NetScaler account via session token theft.

Oct 31, 2023: Mandiant released campaign analysis targeting CVE-2023-4966
https://www.mandiant.com/resources/blog/session-hijacking-citrix-cve-2023-4966


Fortinet customers remain protected via the IPS signature "HTTP.Header.Overly.Long.Host.Field.Value" to detect and block any attack targeting the vulnerable Citrix servers and as of now, it has blocked attacks targeting the vulnerability on more than 5000 unique IPS devices.

FortiGuard also recommends to update and apply patches provided on the vendor advisory.
https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/

FortiGuard Cybersecurity Framework

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.


PROTECT
  • IPS

DETECT
  • Outbreak Detection

  • Threat Hunting

RESPOND
  • Assisted Response Services

  • Automated Response

RECOVER
  • NOC/SOC Training

  • End-User Training

IDENTIFY
  • Attack Surface Hardening

  • Business Reputation

Threat Intelligence

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.


Loading ...

Indicators of compromise Indicators of compromise
IOC Indicator List
Indicator Type Status
116.204.211.185 ip Active
146.70.53.153 ip Active
38745539b71cf201bb502437f891d799 file Active
lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6j... domain Active
lockbitsupdwon76nzykzblcplixwts4n4zoecugz2bxabt... domain Active
lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxd... domain Active
lockbitsupo7vv5vcl3jxpsdviopwvasljqcstym6efhh6o... domain Active
lockbitsupq3g62dni2f36snrdb4n5qzqvovbtkt5xffw3d... domain Active
lockbitsupqfyacidr6upt6nhhyipujvaablubuevxj6xy3... domain Active
lockbitsupt7nr3fa6e7xyb73lk6bw6rcneqhoyblniiabj... domain Active
lockbitsupuhswh4izvoucoxsbnotkmgq6durg7kficg6u3... domain Active
lockbitsupxcjntihbmat4rrh7ktowips2qzywh6zer5r3x... domain Active
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633h... url Active
http://lockbitsupt7nr3fa6e7xyb73lk6bw6rcneqhoyb... url Active
http://lockbitsupuhswh4izvoucoxsbnotkmgq6durg7k... url Active
198.50.168.189 ip Active
62.204.41.108 ip Active
5.182.37.20 ip Active
23.95.146.52 ip Active
5.188.86.204 ip Active
198.54.132.37 ip Active
62.233.50.25 ip Active
45.134.26.2 ip Active
193.201.9.224 ip Active
188.166.172.12 ip Active
81.19.135.226 ip Active
adobe-us-updatefiles.digital domain Active
164.90.224.236 ip Active
167.71.240.230 ip Active
167.71.50.149 ip Active
167.99.48.250 ip Active
170.64.196.163 ip Active
173.230.147.157 ip Active
103.140.186.146 ip Active
103.73.67.95 ip Active
104.233.167.19 ip Active
104.238.154.214 ip Active
107.173.141.176 ip Active
108.181.26.106 ip Active
116.115.100.186 ip Active
128.199.75.99 ip Active
13.127.25.211 ip Active
141.147.153.244 ip Active
142.93.141.67 ip Active
148.135.95.201 ip Active
152.165.126.141 ip Active
152.32.157.12 ip Active
156.234.193.62 ip Active
156.234.193.79 ip Active
158.247.219.29 ip Active
164.90.192.58 ip Active
164.92.69.183 ip Active
164.92.83.110 ip Active
165.140.8.246 ip Active
167.172.52.144 ip Active
168.100.9.178 ip Active
170.64.208.177 ip Active
175.142.200.166 ip Active
178.128.176.153 ip Active
180.110.31.246 ip Active
180.72.161.50 ip Active
185.196.9.232 ip Active
185.82.200.130 ip Active
187.104.140.81 ip Active
188.214.157.115 ip Active
192.169.6.215 ip Active
194.156.120.205 ip Active
194.87.79.109 ip Active
198.211.105.192 ip Active
20.62.196.122 ip Active
203.160.80.250 ip Active
206.166.251.96 ip Active
206.189.179.132 ip Active
206.189.87.28 ip Active
206.237.11.149 ip Active
206.237.11.2 ip Active
216.128.141.153 ip Active
220.241.130.233 ip Active
23.224.55.50 ip Active
38.54.104.182 ip Active
38.54.105.232 ip Active
38.54.107.229 ip Active
38.54.16.128 ip Active
38.54.76.74 ip Active
38.54.95.150 ip Active
45.153.231.193 ip Active
45.55.134.29 ip Active
45.56.162.254 ip Active
5.8.16.33 ip Active
64.176.173.34 ip Active
64.176.224.56 ip Active
66.154.106.13 ip Active
66.154.106.130 ip Active
67.83.53.146 ip Active
68.225.134.82 ip Active
69.30.231.226 ip Active
71.169.48.51 ip Active
78.153.139.228 ip Active
8.222.170.105 ip Active
8.44.149.254 ip Active
Indicators of compromise Indicators of compromise
IOC Threat Activity

Last 30 days

Chg

Avg 0