{
  "id": "CVE-2023-4966",
  "vendor_project": "Citrix",
  "product": "NetScaler ADC and Gateway",
  "description": "Sensitive information disclosure vulnerability ('Citrix Bleed') allowing unauthenticated session token hijacking exploited by LockBit 3.0 affiliates.",
  "kev_date_added": "2023-10-18",
  "cvss": 9.4,
  "severity": "Critical",
  "advisories": [
    "AA23-325A"
  ],
  "cited_in_cases": [
    {
      "slug": "lockbit-ransomware-takedown",
      "title": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)",
      "actor_slug": "lockbit-group"
    }
  ],
  "indictment_cited": true
}