peter bassill · operator
$ cve CVE-2023-6548 JSON

CVE-2023-6548 KEV

5.5
MEDIUM · CVSS 3.1 · EPSS 3.2% (pctl 88)

Patch first

On CISA KEV — known exploited in the wild, due 2024-01-24.

Description

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS3.19% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2024-01-24
Public exploitnone known
Published2024-01-17
Last modified2026-06-17

CISA KEV

NameCitrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Added2024-01-17
Due2024-01-24
Vendor / productCitrix / NetScaler ADC and NetScaler Gateway
Ransomware usenone reported

Affected (2)

VendorProduct
citrixnetscaler application delivery controller
citrixnetscaler gateway

References

→ the Explorer  ·  watch your stack  ·  NVD