Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: CVE-2023-3519 Citrix RCE #336

Open
am0o0 opened this issue Aug 2, 2023 · 1 comment
Open

PRP: CVE-2023-3519 Citrix RCE #336

am0o0 opened this issue Aug 2, 2023 · 1 comment
Assignees
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Accepted

Comments

@am0o0
Copy link
Contributor

am0o0 commented Aug 2, 2023

Hi, I like to start implementing a Tsunami plugin for Citrix NetScaler ADC and Gateway RCE.
As we can see in attackerkb the setup is easy and we can download the vulnerable version from a simple registered citrix account. I can host The ovf file for you, Also the dev/test license can be obtained easily after creating a new account to setup and test the plugin.
from the mentioned blog post:

On July 21, BishopFox reported that there are about 61,000 potentially vulnerable Citrix appliances on the internet, and suggested that about 35% (21k) were vulnerable at the time.

@maoning
Copy link
Collaborator

maoning commented Aug 9, 2023

Hi @amammad ,

Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!

@maoning maoning self-assigned this Aug 9, 2023
@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Feb 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Accepted
Projects
None yet
Development

No branches or pull requests

3 participants