CVE-2023-6548 KEV
5.5
MEDIUM · CVSS 3.1 · EPSS 3.2% (pctl 88)
Patch first
On CISA KEV — known exploited in the wild, due 2024-01-24.
Description
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Scoring
| CVSS | 5.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 3.19% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2024-01-24 |
| Public exploit | none known |
| Published | 2024-01-17 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability |
|---|---|
| Added | 2024-01-17 |
| Due | 2024-01-24 |
| Vendor / product | Citrix / NetScaler ADC and NetScaler Gateway |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| citrix | netscaler application delivery controller |
| citrix | netscaler gateway |
References
- https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549
- https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548
→ the Explorer · watch your stack · NVD