{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gateway/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*","cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*","cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*","cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-3519"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ADC","Gateway"],"_cs_severities":["critical"],"_cs_tags":["citrix","cve-2023-3519","saml","exploitation"],"_cs_type":"threat","_cs_vendors":["Citrix"],"content_html":"\u003cp\u003eThis threat brief focuses on potential exploitation attempts targeting Citrix ADC (Application Delivery Controller) instances vulnerable to CVE-2023-3519. This vulnerability is a SAML processing overflow issue that can lead to memory corruption. Publicly disclosed in July 2023, CVE-2023-3519 allows unauthenticated attackers to perform arbitrary code execution on affected systems. Observed exploitation includes POST requests to specific web endpoints indicative of attempts to trigger this vulnerability. Successful exploitation could allow attackers to gain a foothold within the targeted network, leading to further malicious activities. This activity is significant because it involves a critical vulnerability in a widely used application delivery controller.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a vulnerable Citrix ADC instance exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted POST request to one of the following vulnerable endpoints: \u003ccode\u003e/cgi/logout\u003c/code\u003e, \u003ccode\u003e*/saml/activelogin\u003c/code\u003e, \u003ccode\u003e*/saml/login\u003c/code\u003e, \u003ccode\u003e/cgi/samlart?samlart=*\u003c/code\u003e, \u003ccode\u003e/cgi/samlauth\u003c/code\u003e, \u003ccode\u003e/gwtest/formssso?event=start\u0026amp;target=*\u003c/code\u003e, or \u003ccode\u003e/netscaler/ns_gui/vpn/*\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe crafted POST request exploits the SAML processing overflow vulnerability (CVE-2023-3519) to corrupt memory.\u003c/li\u003e\n\u003cli\u003eThe memory corruption leads to arbitrary code execution within the Citrix ADC appliance.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the code execution to establish a persistent foothold on the system, potentially installing a web shell.\u003c/li\u003e\n\u003cli\u003eThe attacker escalates privileges to gain administrative control over the Citrix ADC.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the compromised Citrix ADC as a pivot point to move laterally within the internal network.\u003c/li\u003e\n\u003cli\u003eThe attacker exfiltrates sensitive data, deploys ransomware, or causes disruption to critical services.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-3519 can have severe consequences, including arbitrary code execution, privilege escalation, and complete system compromise. This can lead to data breaches, service disruptions, and financial losses. The vulnerability affects Citrix ADC and Citrix Gateway, which are widely used in various sectors. The \u0026quot;X-Force Uncovers Global NetScaler Gateway Credential Harvesting Campaign\u0026quot; reference indicates this vulnerability has been actively exploited in credential harvesting campaigns.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules in this brief to your SIEM to detect potential exploitation attempts against Citrix ADC instances.\u003c/li\u003e\n\u003cli\u003eApply the patches provided by Citrix for CVE-2023-3519 as detailed in the Citrix security bulletin (\u003ca href=\"https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467)\"\u003ehttps://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467)\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReview web server logs for POST requests to the vulnerable endpoints listed in the attack chain to identify potential exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnsure that the Web datamodel is populated from a supported Technology Add-On in Splunk as mentioned in the \u0026quot;how_to_implement\u0026quot; section.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T18:02:11Z","date_published":"2024-01-29T10:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-citrix-adc-cve-2023-3519/","summary":"Exploitation attempts against Citrix ADC via CVE-2023-3519, a SAML processing overflow, detected through specific POST requests, could lead to arbitrary code execution, privilege escalation, or service disruption.","title":"Citrix ADC CVE-2023-3519 Exploitation Attempts","url":"https://feed.craftedsignal.io/briefs/2024-01-citrix-adc-cve-2023-3519/"}],"language":"en","title":"CraftedSignal Threat Feed - Gateway","version":"https://jsonfeed.org/version/1.1"}