• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Recently patched Citrix NetScaler bug exploited as zero-day since August

Bill Toulas by Bill Toulas
October 18, 2023
Reading Time: 2 mins read
0
Recently patched Citrix NetScaler bug exploited as zero-day since August

Citrix

RELATED POSTS

HTC Global Services confirms cyberattack after data leaked online

Multiple NFT collections at risk by flaw in open-source library

Kali Linux 2023.4 released with GNOME 45 and 15 new tools

A critical vulnerability tracked as CVE-2023-4966 in Citrix NetScaler ADC/Gateway devices has been actively exploited as a zero-day since late August, security researchers announced.

The security issue is an information disclosure and received a fix last week. It allows attackers to access secrets in appliances configured as gateways of authentication, authorization, and accounting (AAA) virtual servers.

In a security bulletin on October 10 with few technical details, Citrix strongly urged customers to install the available update without delay.

A report from Mandiant disclosed that it found signs of CVE-2023-4966 being exploited in the wild since August for stealing authentication sessions and hijacking accounts.

“Mandiant has identified zero-day exploitation of this vulnerability in the wild beginning in late August 2023,” says the cybersecurity company.

“Successful exploitation could result in the ability to hijack existing authenticated sessions, therefore bypassing multifactor authentication or other strong authentication requirements” – Mandiant

The company also warns that hijacked sessions persist even after installing the security update. Depending on the permissions of the hijacked account, the attackers may leverage the method to move laterally or to breach more accounts.

Buy JNews
ADVERTISEMENT

Security researchers observed CVE-2023-4966 being exploited for access on infrastructure belonging to government organizations and technology companies.

Fixing and mitigation

Apart from applying the patch from Citrix, Mandiant published a document with additional remediation recommendations for NetScaler ADC/Gateway administrators with the following suggestions:

  1. Restrict ingress IP addresses if immediate patching isn’t feasible.
  2. Terminate all sessions post-upgrade and run the CLI command: clear lb persistentSessions .
  3. Rotate credentials for identities accessing vulnerable appliances.
  4. If suspicious activity is detected, especially with single-factor authentication, rotate a broader scope of credentials.
  5. For detected web shells or backdoors, rebuild appliances with the latest clean-source image.
  6. If restoring from backup, ensure no backdoors are in the backup configuration.
  7. Limit external attack exposure by restricting ingress to trusted IPs.

Also, upgrading the appliances to the following firmware versions should be prioritized:

  • NetScaler ADC and NetScaler Gateway 14.1-8.50 and later
  • NetScaler ADC and NetScaler Gateway 13.1-49.15 and later releases of 13.1
  • NetScaler ADC and NetScaler Gateway 13.0-92.19 and later releases of 13.0 
  • NetScaler ADC 13.1-FIPS 13.1-37.164 and later releases of 13.1-FIPS 
  • NetScaler ADC 12.1-FIPS 12.1-55.300 and later releases of 12.1-FIPS 
  • NetScaler ADC 12.1-NDcPP 12.1-55.300 and later releases of 12.1-NdcPP

This is the second zero-day flaw Citrix fixes in its products this year. A previous one, identified as CVE-2023-3519, was exploited in the wild in early July and received a fix a few of weeks later.

Share54Tweet34Pin12
Bill Toulas

Bill Toulas

Related Posts

HTC Global Services confirms cyberattack after data leaked online
Cyber Security

HTC Global Services confirms cyberattack after data leaked online

December 5, 2023
Multiple NFT collections at risk by flaw in open-source library
Cyber Security

Multiple NFT collections at risk by flaw in open-source library

December 5, 2023
Kali Linux 2023.4 released with GNOME 45 and 15 new tools
Cyber Security

Kali Linux 2023.4 released with GNOME 45 and 15 new tools

December 5, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates
Cyber Security

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates
Cyber Security

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates
Cyber Security

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023

Recommended Stories

Video Review: AirPods Pro 2 After Six Months

March 10, 2023
How the FBI proved a remote admin tool was actually malware

How the FBI proved a remote admin tool was actually malware

March 10, 2023

Trump pivots hard away from fight against unvanquished pandemic

September 27, 2022

Popular Stories

  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • A Brief History of All the Women Who Have Won the Nobel Prize

    136 shares
    Share 54 Tweet 34
  • Will XRP make a comeback after the recent price decline? Data suggests…

    136 shares
    Share 54 Tweet 34
  • Gowalla returns to see if location-based networking is ready for its mainstream moment

    136 shares
    Share 54 Tweet 34
  • Saudi Arabia Seeks U.S. Security Pledges, Nuclear Help for Peace with Israel

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • Ethereum spot ETF race heats up: This cohort takes an interest
  • Of SHIB’s surging burn rate and BONE’s role in it all
  • Should Blur investors be concerned about the dip in prices?

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?