Critical Citrix NetScaler CVE-2023-3519 Exploit Steals Config Data
Key Takeaways A critical vulnerability, CVE-2023-3519, in Citrix NetScaler ADC and NetScaler Gateway is under active exploitation. Attackers are using the flaw to execute arbitrary commands, deploy...
Key Takeaways
- A critical vulnerability, CVE-2023-3519, in Citrix NetScaler ADC and NetScaler Gateway is under active exploitation.
- Attackers are using the flaw to execute arbitrary commands, deploy web shells, create privileged accounts, and steal configuration data.
- The vulnerability carries a CVSS 4.0 score of 9.5 (Critical) and affects default deployments without additional features enabled.
- Emergency patches were released by Citrix on September 27, 2023, and immediate application is crucial.
- Forensic investigation is recommended even after patching, as exploitation may have already occurred.
Widespread Exploitation of Critical Citrix NetScaler Flaw Discovered
Hackers are actively exploiting CVE-2023-3519, a severe vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway products. This critical flaw allows unauthenticated command execution, enabling attackers to deploy web shells, establish persistent access, and exfiltrate sensitive appliance configuration data. The observed malicious activity extends beyond mere reconnaissance, indicating a concerted effort to compromise systems and maintain control.
Table Of Content
Citrix has assigned a CVSS 4.0 score of 9.5 to CVE-2023-3519, categorizing it as critical. The vendor confirmed that vulnerable default installations are exposed to this exploit even without any specific extra features being enabled. The confirmed zero-day exploitation prompted Citrix to issue emergency security updates on September 27, 2023.
Researchers from LevelBlue’s Threat Hunt Operations & Research team identified suspicious authentication events across multiple client environments. Their subsequent September 30 technical report detailed the use of Python and Perl payloads. These payloads facilitate reverse shells, the creation of privileged accounts, installation of web shells, and attempts to steal configuration files. While the findings confirm exploitation attempts, they do not definitively establish the success rate of every individual attack.
Attack Patterns and Payload Analysis
Attackers have been observed embedding shell commands within username fields, often alongside strings such as `pitboss`, `NSPPE`, and `unexpectedly died`. Initial probes frequently involve commands like `whoami` to verify command execution, followed by `curl` or `wget` to download additional malicious code.
Further analysis revealed commands designed to copy the appliance’s primary configuration into a web-accessible directory or to archive the entire configuration folder for later retrieval. One notable exploitation technique utilized command substitution and `${IFS}` to represent whitespace, bypassing detection mechanisms that might flag literal spaces in commands. This specific method provides a distinct pattern for defenders to identify: suspicious authentication fields containing crash-related text combined with commands for data exfiltration.
The Python payload is designed to overwrite a legitimate appliance component with reverse-shell code. This code then initiates an outbound connection over TCP port 443, effectively redirecting standard input and output to the attacker’s command and control server, establishing an interactive shell. The initial script also includes functionality to terminate existing processes associated with the targeted component, ensuring the successful deployment of the reverse shell.
Web Shells and Configuration Theft Tactics
The Perl payload, a more sophisticated tool, aims to establish long-term persistence and facilitate data exfiltration. It creates a local superuser account, archives the critical configuration directory, and then attempts to upload this archive to attacker-controlled infrastructure. Subsequently, the payload removes both the archive and itself, making forensic analysis challenging. This means that the absence of these files does not necessarily indicate a failed attack or that no data was exfiltrated.
Furthermore, the Perl payload alters shell permissions to `6555` and installs a PHP web shell. It modifies the HTTP server configuration to enable PHP execution and expose the web shell through URLs crafted to resemble legitimate CSS resources. This tactic mirrors previous NetScaler web shell discoveries reported by Google, though LevelBlue has not confirmed if it is the exact same malware variant.
The deployed web shell provides remote command execution capabilities, file upload, and download functions. Coupled with the creation of an administrator account, these actions grant attackers multiple avenues for maintaining persistent control over the compromised appliance beyond the initial exploit.
Security teams are advised to meticulously examine authentication logs for unusual entries, investigate unexpected access to configuration files, scan for new files within web directories, monitor for unauthorized changes to privileged accounts, and scrutinize outbound network traffic originating from suspicious login events. LevelBlue specifically warns that a failed authentication attempt does not equate to a failed command injection; post-authentication activities must still be investigated.
While known Indicators of Compromise (IoCs) such as IP addresses and hashes can aid in detection, attackers frequently modify these. More enduring indicators include embedded shell commands within authentication data, alterations to core appliance components, and configuration archives placed in web-accessible locations. A comprehensive review of network records, alongside file and account modifications, is essential to determine the extent of compromise and whether a persistent shell or data exfiltration occurred. Administrators must consult Citrix’s official security bulletin and apply the appropriate supported updates immediately. The initial urgent patch guidance for NetScaler also emphasized the importance of investigating for potential compromise, rather than assuming an appliance is clean simply because it has been updated.
The bulletin specifies fixes for this vulnerability in versions 14.1-73.37 and 13.1-64.23, along with corresponding FIPS and NDcPP builds. These represent the minimum required fixes detailed in the advisory, not necessarily the latest available releases. Organizations should always refer to the most current vendor guidance when selecting updates, especially if other NetScaler vulnerabilities are also applicable to their environment.
Indicators of Compromise (IoCs)
| Type | Indicator | Observed role |
|---|---|---|
| IPv4 | 70.172.58[.]168 |
Exploitation source |
| IPv4 | 45.141.21[.]130 |
Reverse-shell C2 |
| IPv4 | 162.243.36[.]88 |
Exploitation source |
| IPv4 | 173.40.135[.]209 |
Exploitation source |
| IPv4 | 47.230.224[.]154 |
Exploitation source |
| IPv4 | 23.27.143[.]20 |
Exploit source; payload host |
| IPv4 | 62.133.62[.]80 |
Payload host |
| IPv4 | 64.94.85[.]67 |
Exploit, payload, exfiltration infrastructure |
| IPv4 | 92.118.204[.]229 |
Command-execution testing |
| IPv4 | 87.224.84[.]82 |
Configuration-staging attempt |
| IPv4 | 31.56.197[.]72 |
Payload host |
| URL | hxxp://62.133.62[.]80:80/xd7h/x |
Payload download |
| URL | hxxp://23.27.143[.]20:9000/main.py |
Python reverse-shell payload |
| URL | hxxp://64.94.85[.]67:443/update_c08937.pl |
Perl payload |
| URL | hxxp://64.94.85[.]67:443/update_result_3567cs.tgz |
Configuration exfiltration endpoint |
| URL | hxxp://31.56.197[.]72:9090/lula |
Payload download |
| SHA-256 | e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c |
main.py |
| SHA-256 | 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 |
update_c08937.pl |
| File | /var/netscaler/logon/LogonPoint/.local_journal |
PHP web shell |
| File | /tmp/update_result_3567cs.tgz |
Staged configuration archive |
| File | /var/netscaler/logon/insight-new.js |
Staged configuration |
| File | /var/netscaler/logon/LogonPoint/xua.html |
Staged configuration archive |
| Account | sec_monitor |
Created superuser account |
| Component | /var/python/bin/customsnmpd |
Reverse-shell overwrite target |
| Configuration | /flash/nsconfig/ns.conf |
Modified account configuration |
| Directory | /flash/nsconfig |
Archived configuration data |
| Configuration | /etc/httpd.conf |
PHP and alias changes |
| Permissions | /bin/sh: 6555 |
Altered shell permissions |
| Alias | LogonUISimple.html.style.min.css |
Disguised web-shell resource |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Patch Immediately: Apply the latest security updates for Citrix NetScaler ADC and NetScaler Gateway as specified in Citrix’s official security bulletin. Ensure your versions are at least 14.1-73.37, 13.1-64.23, or their corresponding FIPS and NDcPP builds.
- Conduct Forensic Analysis: Even after patching, assume potential compromise and perform a thorough forensic investigation. Examine authentication logs, network traffic, file system changes, and configuration files for any signs of exploitation described in this report.
- Monitor for Suspicious Activity: Implement continuous monitoring for unusual authentication attempts, unexpected outbound connections from NetScaler appliances, new or modified files in web directories, and the creation of unauthorized privileged accounts.
- Review Configuration and Permissions: Audit `/flash/nsconfig`, `/etc/httpd.conf`, and `/bin/sh` permissions for any unauthorized modifications.
- Utilize IoCs: Integrate the provided Indicators of Compromise (IoCs) into your security information and event management (SIEM) systems and threat intelligence platforms to aid in detection.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.