CVE-2023-6548
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
El control inadecuado de la generación de código ("inyección de código") en NetScaler ADC y NetScaler Gateway permite a un atacante con acceso a NSIP, CLIP o SNIP con interfaz de administración realizar una ejecución remota de código autenticado (con privilegios bajos) en Management Interface.
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2023-12-06 CVE Reserved
- 2024-01-17 CVE Published
- 2024-01-17 Exploited in Wild
- 2024-01-24 KEV Due Date
- 2024-03-04 First Exploit
- 2024-08-02 CVE Updated
- 2024-08-25 EPSS Updated
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 12.1 < 12.1-55.302 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 12.1 < 12.1-55.302" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 12.1 < 12.1-55.302 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 12.1 < 12.1-55.302" | ndcpp |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.0 < 13.0-92.21 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.0 < 13.0-92.21" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.1 < 13.1-37.176 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.1 < 13.1-37.176" | fips |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 13.1 < 13.1-51.15 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 13.1 < 13.1-51.15" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Application Delivery Controller Search vendor "Citrix" for product "Netscaler Application Delivery Controller" | >= 14.1 < 14.1-12.35 Search vendor "Citrix" for product "Netscaler Application Delivery Controller" and version " >= 14.1 < 14.1-12.35" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 13.0 < 13.0-92.21 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 13.0 < 13.0-92.21" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 13.1 < 13.1-51.15 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 13.1 < 13.1-51.15" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | >= 14.1 < 14.1-12.35 Search vendor "Citrix" for product "Netscaler Gateway" and version " >= 14.1 < 14.1-12.35" | - |
Affected
|