Detect CVE-2023-4966 Citrix ADC Sensitive Info Disclosure Attempts in Webserver Logs via Long Host Header

Alerts on GET requests to the OpenID configuration endpoint with an unusually long Host header, indicative of CVE-2023-4966 probing.

FreeReviewedSigma · High · v5
Category
webserver
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-11-28
Updated
2026-07-31
title: Detect CVE-2023-4966 Citrix ADC Sensitive Info Disclosure Attempts in Webserver Logs via Long Host Header
id: a52eb475-8fba-435f-831a-b0d25d41be54
related:
  - id: 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
    type: similar
  - id: ff349b81-617f-4af4-924f-dbe8ea9bab41
    type: similar
  - id: aee7681f-b53d-4594-a9de-ac51e6ad3362
    type: similar
  - id: a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
    type: derived
status: test
description: This rule flags HTTP GET requests to the OpenID configuration path used in OAuth/OIDC flows while the host header value matches a very long pattern (150+ characters). Attackers may leverage this behavior to probe or attempt exploitation of the Citrix ADC and NetScaler Gateway sensitive information disclosure issue. It relies on webserver telemetry fields for request method, URI stem, and host header length/pattern matching.
references:
  - https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
  - https://attackerkb.com/topics/2faW2CxJgQ/cve-2023-4966
  - https://www.rapid7.com/blog/post/2023/10/25/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability/
  - https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
  - https://github.com/assetnote/exploits/tree/main/citrix/CVE-2023-4966
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-4966/web_exploit_cve_2023_4966_citrix_sensitive_information_disclosure_exploit_attempt.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-11-28
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2023-4966
  - detection.emerging-threats
logsource:
  category: webserver
detection:
  selection:
    cs-method: GET
    cs-uri-stem|contains: /oauth/idp/.well-known/openid-configuration
    cs-host|re: .{150}
  condition: selection
falsepositives:
  - Vulnerability scanners
level: high
license: DRL-1.1