Detect CVE-2023-4966 Citrix ADC Sensitive Info Disclosure Attempts in Webserver Logs via Long Host Header
Alerts on GET requests to the OpenID configuration endpoint with an unusually long Host header, indicative of CVE-2023-4966 probing.
- Category
- webserver
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-11-28
- Updated
- 2026-07-31
ATT&CK techniques
Initial AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags HTTP GET requests to the OpenID configuration path used in OAuth/OIDC flows while the host header value matches a very long pattern (150+ characters). Attackers may leverage this behavior to probe or attempt exploitation of the Citrix ADC and NetScaler Gateway sensitive information disclosure issue. It relies on webserver telemetry fields for request method, URI stem, and host header length/pattern matching.
Reporting behind it
- support.citrix.comhttps://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
- attackerkb.comhttps://attackerkb.com/topics/2faW2CxJgQ/cve-2023-4966
- rapid7.comhttps://www.rapid7.com/blog/post/2023/10/25/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability/
- assetnote.iohttps://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
- github.comhttps://github.com/assetnote/exploits/tree/main/citrix/CVE-2023-4966
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-4966/web_exploit_cve_2023_4966_citrix_sensitive_information_disclosure_exploit_attempt.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Detect CVE-2023-4966 Citrix ADC Sensitive Info Disclosure Attempts in Webserver Logs via Long Host Header
id: a52eb475-8fba-435f-831a-b0d25d41be54
related:
- id: 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
type: similar
- id: ff349b81-617f-4af4-924f-dbe8ea9bab41
type: similar
- id: aee7681f-b53d-4594-a9de-ac51e6ad3362
type: similar
- id: a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
type: derived
status: test
description: This rule flags HTTP GET requests to the OpenID configuration path used in OAuth/OIDC flows while the host header value matches a very long pattern (150+ characters). Attackers may leverage this behavior to probe or attempt exploitation of the Citrix ADC and NetScaler Gateway sensitive information disclosure issue. It relies on webserver telemetry fields for request method, URI stem, and host header length/pattern matching.
references:
- https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
- https://attackerkb.com/topics/2faW2CxJgQ/cve-2023-4966
- https://www.rapid7.com/blog/post/2023/10/25/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability/
- https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
- https://github.com/assetnote/exploits/tree/main/citrix/CVE-2023-4966
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-4966/web_exploit_cve_2023_4966_citrix_sensitive_information_disclosure_exploit_attempt.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-11-28
tags:
- attack.initial-access
- attack.t1190
- cve.2023-4966
- detection.emerging-threats
logsource:
category: webserver
detection:
selection:
cs-method: GET
cs-uri-stem|contains: /oauth/idp/.well-known/openid-configuration
cs-host|re: .{150}
condition: selection
falsepositives:
- Vulnerability scanners
level: high
license: DRL-1.1