Kemp Support, how can we help?

The latest application delivery knowledge and expertise at your fingertips.

Detection of CVE-2023-3519 in ADS

 

Information

 

Summary:

Possibilities of detection of NetScaler CVE-2023-3519 in the Flowmon ADS module.

Environment:

Product: Flowmon ADS

Version: Any

Platform: Any

Question/Problem Description:

Is it possible to detect CVE-2023-3519?

Steps to Reproduce:  
Error Message:  
Defect Number:  
Enhancement Number:  
Cause:  
Resolution:

There is no specific method or behavior pattern to detect CVE-2023-3519 in ADS. 

It is possible to detect the behavior of the attacker when the NetScaler ADC was attacked like the port scanning (mainly ports 80, 443, 445), anomalies in DNS/LDAP traffic, high connection count with ADC, or higher traffic transfers in the network. 

Workaround:  
Notes: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a

Was this article helpful?
0 out of 0 found this helpful

Comments