CVE-2023-3519
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
10
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
Unauthenticated remote code execution
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-07-05 CVE Reserved
- 2023-07-19 CVE Published
- 2023-07-19 Exploited in Wild
- 2023-07-21 First Exploit
- 2023-08-09 KEV Due Date
- 2024-08-02 CVE Updated
- 2024-10-23 EPSS Updated
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://attackerkb.com/topics/si09VNJhHh/cve-2023-3519 |
URL | Date | SRC |
---|---|---|
https://github.com/BishopFox/CVE-2023-3519 | 2023-08-23 | |
https://github.com/mr-r3b00t/CVE-2023-3519 | 2023-07-21 | |
https://github.com/SalehLardhi/CVE-2023-3519 | 2023-07-21 | |
https://github.com/Chocapikk/CVE-2023-3519 | 2023-08-30 | |
https://github.com/Mohammaddvd/CVE-2023-3519 | 2023-10-27 | |
https://github.com/d0rb/CVE-2023-3519 | 2023-07-21 | |
https://github.com/KR0N-SECURITY/CVE-2023-3519 | 2023-07-21 | |
https://github.com/passwa11/CVE-2023-3519 | 2023-08-04 | |
https://github.com/JonaNeidhart/CVE-2023-3519-BackdoorCheck | 2023-08-31 | |
http://packetstormsecurity.com/files/173997/Citrix-ADC-NetScaler-Remote-Code-Execution.html | 2024-08-02 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 12.1 < 12.1-55.297 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 12.1 < 12.1-55.297" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 12.1 < 12.1-55.297 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 12.1 < 12.1-55.297" | ndcpp |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.0 < 13.0-91.13 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.0 < 13.0-91.13" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.1 < 13.1-37.159 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.1 < 13.1-37.159" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.1 < 13.1-49.13 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.1 < 13.1-49.13" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | 11.1-65.22 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version "11.1-65.22" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 13.0 < 13.0-91.13 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 13.0 < 13.0-91.13" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 13.1 < 13.1-49.13 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 13.1 < 13.1-49.13" | - |
Affected
|