CVE-2023-6548 - Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Project:Citrix
Product:NetScaler ADC and NetScaler Gateway
Date Added:2024-01-17Due Date:2024-01-24
Vulnerability Name
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Description
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549
https://nvd.nist.gov/vuln/detail/CVE-2023-6548
Related News Articles
Citrix warns admins to manually mitigate PuTTY SSH client bugMay 10, 2024