Executive brief
A buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway allows an unauthenticated attacker to cause a denial-of-service (DoS) or perform an out-of-bounds memory read. The vulnerability is exploitable when the device is configured as a Gateway or AAA virtual server.
Affected products
- Citrix NetScaler ADC 13.0 before 13.0-92.21, 13.1 before 13.1-51.15, 14.1 before 14.1-12.35, 12.1-FIPS before 12.1-55.302, 13.1-FIPS before 13.1-37.176, 12.1-NDcPP before 12.1-55.302
- Citrix NetScaler Gateway 13.0 before 13.0-92.21, 13.1 before 13.1-51.15, 14.1 before 14.1-12.35
Timeline
- 2024-01-17: disclosed
- 2024-01-17: kev added: Added to CISA KEV catalog due to active exploitation.
- 2024-01-17: advisory: Citrix security bulletin CTX584986 published.