By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Critical NetScaler Flaw Bypasses Authentication

Citrix has issued urgent updates to resolve two significant security vulnerabilities affecting its NetScaler Application Delivery Controller (ADC) and NetScaler Gateway products. The most critical of these is an authentication bypass flaw that allows unauthorized access to protected resources. This vulnerability, designated CVE-2023-4966, carries a critical severity rating, indicating a high risk of exploitation. The flaw specifically impacts customer-managed NetScaler ADC and NetScaler Gateway instances, including certain builds that adhere to Federal Information Processing Standards (FIPS) and National Institute of Standards and Technology (NIST) National Security Systems (NSS) Special Publication 800-135 (NDcPP) requirements. Additionally, the SecurAccess functionality within these products is also affected.
Beyond the critical authentication bypass, a second vulnerability, CVE-2023-4967, has also been addressed. This separate issue impacts NetScaler ADC, NetScaler Gateway, and NetScaler SD-WAN WANOP editions. While not rated as critical as the authentication bypass, it is described as an important-severity flaw. The exact nature and impact of CVE-2023-4967 have not been fully detailed by Citrix, but its classification as 'important' suggests it could still pose a significant risk to affected systems. The company has provided patches and workarounds to mitigate these vulnerabilities, urging customers to apply them promptly to secure their deployments.
These vulnerabilities come at a time when organizations are increasingly reliant on secure remote access solutions and application delivery controllers. NetScaler ADC and Gateway are widely used by enterprises to manage application traffic, provide secure remote access for employees, and enhance application performance and availability. The potential for an authentication bypass could allow attackers to gain unauthorized access to sensitive internal applications and data, bypassing established security controls. The inclusion of FIPS and NDcPP compliant builds in the affected list suggests that even highly secured environments may be vulnerable if not updated.
Citrix, a subsidiary of Cloud Software Group, is a prominent provider of virtualization, networking, and cloud computing technologies. Its NetScaler suite is a cornerstone for many businesses managing complex IT infrastructures. The company's advisory emphasizes the importance of immediate action, providing specific guidance on how to identify if a deployment is affected and the steps required to remediate the vulnerabilities. Customers are advised to consult the official Citrix security bulletin for detailed instructions on applying the necessary updates and configurations. The prompt release of patches indicates Citrix's commitment to addressing security threats and protecting its user base from potential cyberattacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.