NetScaler ADC and Gateway
CVE-2023-4967: Denial of service
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Published
ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 3.1 8.2
EPSS0.89%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| NetScaler ADC 14.1 | 8.50 or later |
| NetScaler ADC 13.1 | 49.15 or later |
| NetScaler ADC 13.0 | 92.19 or later |
| NetScaler ADC 13.1-FIPS | 37.164 or later |
| NetScaler ADC 12.1-FIPS | 55.300 or later |
| NetScaler ADC 12.1-NDcPP | 55.300 or later |
| NetScaler Gateway 14.1 | 8.50 or later |
| NetScaler Gateway 13.1 | 49.15 or later |
| NetScaler Gateway 13.0 | 92.19 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.