CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy

Rule Info

Name
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
Date
2023-11-28 00:00:00
Modified
None
Id
aee7681f-b53d-4594-a9de-ac51e6ad3362
Tags
attack.initial-access attack.t1190 cve.2023-4966 detection.emerging-threats
Type
Community Rule