Executive brief
Citrix NetScaler ADC and NetScaler Gateway are vulnerable to unauthenticated remote code execution via code injection. This vulnerability allows an attacker to execute arbitrary code on the target appliance without requiring prior authentication.
Affected products
- Citrix NetScaler ADC 13.1 before 13.1-49.13, 13.0 before 13.0-91.13, 12.1 before 12.1-55.297, 11.1-65.22
- Citrix NetScaler Gateway 13.1 before 13.1-49.13, 13.0 before 13.0-91.13
Timeline
- 2023-07-19: disclosed
- 2023-07-19: advisory
- 2023-07-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-07-19: exploited: Reported as exploited in the wild at time of publication