CVE-2023-4967: Citrix NetScaler Application Delivery Controller
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Affected products
- Citrix NetScaler Application Delivery Controller: from 13.0, before 13.0-92.19 (fixed in 13.0-92.19); from 13.1, before 13.1-49.15 (fixed in 13.1-49.15); from 14.1, before 14.1-8.50 (fixed in 14.1-8.50); from 12.1, up to and including 12.1-55.300; from 13.1, up to and including 13.1-37.164
- Citrix NetScaler Gateway: from 13.0, before 13.0-92.19 (fixed in 13.0-92.19); from 13.1, before 13.1-49.15 (fixed in 13.1-49.15); from 14.1, before 14.1-8.50 (fixed in 14.1-8.50)
Published 2023-10-27. Last modified 2026-06-17.