μν μμ½ : Citrix Bleed CVE-2023-4966
2023λ 10μ 10μΌ, Citrixλ Netscaler ADC λ° Netscaler Gateway μ νμ λν ν¨μΉλ₯Ό λ°ννμΌλ©°, μ΄ ν¨μΉλ Citrix Bleed(CVE-2023-4966)λΌλ νΉλ³ν μ·¨μ½μ μ μννκΈ° μν κ²μ λλ€. 곡격μλ μ΄ μ·¨μ½μ μ μ¬μ©νμ¬ μΈμ ν ν°μ λμΆν μ μκ³ , Unit 42 μ¬κ³ λμ λ° κ΄λ¦¬λ μν μ¬λ₯ νμ λμ¬μ¨μ΄ κ·Έλ£Ήμ΄ μ΄ μ·¨μ½μ μ μ μ©νλ κ²μ κ΄μ°°νμ΅λλ€.
Threat Brief: Citrix Bleed CVE-2023-4966
On October 10, 2023, Citrix announced a patch for Netscaler ADC and NetScaler Gateway products, which is intended to alleviate the special vulnerability of Citrix Bleed (CVE-20123-4966).The attacker can use this vulnerabilities to leak session tokens, and the Unit 42 accident response and managed threat hunting team observed the ransomware group exploited this vulnerability.
https://unit42.paloaltonetworks.com/threat-brief-cve-2023-4966-netscaler-citrix-bleed/