Junglewise Threat Intelligence

CVE-2023-6548: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

CVE-2023-6548 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-01-17

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway. Vendors: Citrix.

Executive brief

A code injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway allows authenticated users with low privileges to perform remote code execution on the management interface. Exploitation requires access to the NetScaler IP (NSIP), Cluster IP (CLIP), or Subnet IP (SNIP) with management interface access.

Affected products

  • Citrix NetScaler ADC 12.1 before 12.1-55.302, 13.0 before 13.0-92.21, 13.1 before 13.1-51.15, 14.1 before 14.1-12.35
  • Citrix NetScaler Gateway 13.0 before 13.0-92.21, 13.1 before 13.1-51.15, 14.1 before 14.1-12.35

Timeline

  • 2024-01-17: disclosed
  • 2024-01-17: advisory: Citrix security bulletin CTX584986 published
  • 2024-01-17: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2024-01-17: exploited: Reported as exploited in the wild at time of disclosure

Related threats