CVE-2023-4966 Sensitive Info Disclosure Attempt on Citrix ADC via Webserver Logs
Alerts on successful GET requests to the OIDC openid-configuration path that match CVE-2023-4966 related probing patterns.
- Category
- webserver
- Author
- Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT) (SigmaHQ), DRL 1.1
- Published
- 2023-11-28
- Updated
- 2026-07-31
ATT&CK techniques
Initial AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags webserver requests that use the GET method to access the OpenID configuration path under /oauth/idp/.well-known/openid-configuration, returning HTTP 200 responses. Such behavior can indicate an attempt to trigger or observe a sensitive information disclosure condition tied to CVE-2023-4966 on Citrix ADC/NetScaler Gateway. Detection relies on webserver telemetry fields for request method, URI stem matching, and the HTTP status code.
Reporting behind it
- support.citrix.comhttps://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
- attackerkb.comhttps://attackerkb.com/topics/2faW2CxJgQ/cve-2023-4966
- rapid7.comhttps://www.rapid7.com/blog/post/2023/10/25/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability/
- assetnote.iohttps://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
- github.comhttps://github.com/assetnote/exploits/tree/main/citrix/CVE-2023-4966
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-4966/web_exploit_cve_2023_4966_citrix_sensitive_information_disclosure_exploit.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: CVE-2023-4966 Sensitive Info Disclosure Attempt on Citrix ADC via Webserver Logs
id: 550e15fb-a888-47ce-a78b-9761f9b5ce73
related:
- id: ff349b81-617f-4af4-924f-dbe8ea9bab41
type: similar
- id: aee7681f-b53d-4594-a9de-ac51e6ad3362
type: similar
- id: a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
type: similar
- id: 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
type: derived
status: test
description: This rule flags webserver requests that use the GET method to access the OpenID configuration path under /oauth/idp/.well-known/openid-configuration, returning HTTP 200 responses. Such behavior can indicate an attempt to trigger or observe a sensitive information disclosure condition tied to CVE-2023-4966 on Citrix ADC/NetScaler Gateway. Detection relies on webserver telemetry fields for request method, URI stem matching, and the HTTP status code.
references:
- https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
- https://attackerkb.com/topics/2faW2CxJgQ/cve-2023-4966
- https://www.rapid7.com/blog/post/2023/10/25/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability/
- https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
- https://github.com/assetnote/exploits/tree/main/citrix/CVE-2023-4966
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-4966/web_exploit_cve_2023_4966_citrix_sensitive_information_disclosure_exploit.yml
author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT), Huntrule Team
date: 2023-11-28
tags:
- attack.initial-access
- attack.t1190
- cve.2023-4966
- detection.emerging-threats
logsource:
category: webserver
detection:
selection:
cs-method: GET
cs-uri-stem|contains: /oauth/idp/.well-known/openid-configuration
sc-status: 200
condition: selection
falsepositives:
- Vulnerability scanners
level: medium
license: DRL-1.1