⚠ Actively exploited
Added to CISA KEV on 2024-01-17. Federal agencies required to patch by 2024-01-24. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-6548Code Injection in Software Group Netscaler ADC

Severity
8.8HIGHNVD
VulnCheck8.2VulnCheck5.5
EPSS
8.3%
top 7.72%
CISA KEV
KEV
Added 2024-01-17
Due 2024-01-24
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 17
KEV addedJan 17
KEV dueJan 24
Latest updateApr 23
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

NVDcitrix/netscaler_gateway13.013.0-92.21+2
CVEListV5cloud_software_group/netscaler_gateway14.112.35+2
CVEListV5cloud_software_group/netscaler_adc14.112.35+5

🔴Vulnerability Details

3
GHSA
GHSA-w4rw-v3mm-hj8h: [PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR]2024-01-17
VulnCheck
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability2023
VulnCheck
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability2023

📋Vendor Advisories

2
CISA
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability2024-01-17
Citrix
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2023-6548 and CVE-2023-65492024-01-16

🕵️Threat Intelligence

6
Tenable
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends2025-04-23
Bleepingcomputer
Citrix warns admins to manually mitigate PuTTY SSH client bug2024-05-09
Wiz
Crying Out Cloud - February Newsletter | Wiz2024-02-01
Bleepingcomputer
CISA pushes federal agencies to patch Citrix RCE within a week2024-01-17
Bleepingcomputer
Citrix warns of new Netscaler zero-days exploited in attacks2024-01-16