Junglewise Threat Intelligence

CVE-2023-3519: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

CVE-2023-3519 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-07-19

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway. Vendors: Citrix.

Executive brief

Citrix NetScaler ADC and NetScaler Gateway are vulnerable to unauthenticated remote code execution via code injection. This vulnerability allows an attacker to execute arbitrary code on the target appliance without requiring prior authentication.

Affected products

  • Citrix NetScaler ADC 13.1 before 13.1-49.13, 13.0 before 13.0-91.13, 12.1 before 12.1-55.297, 11.1-65.22
  • Citrix NetScaler Gateway 13.1 before 13.1-49.13, 13.0 before 13.0-91.13

Timeline

  • 2023-07-19: disclosed
  • 2023-07-19: advisory
  • 2023-07-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-19: exploited: Reported as exploited in the wild at time of publication

Related threats