← All CVEs

CVE-2023-6548

medium · 5.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2024-01-17Remediation due 2024-01-24

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

5.5
CVSS
3.2%
EPSS (exploit prob.)
88th
EPSS percentile
2024-01-17
Published

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
citrixnetscaler_application_delivery_controller>= 12.1, < 12.1-55.302
citrixnetscaler_application_delivery_controller>= 12.1, < 12.1-55.302
citrixnetscaler_application_delivery_controller>= 13.0, < 13.0-92.21
citrixnetscaler_application_delivery_controller>= 13.1, < 13.1-37.176
citrixnetscaler_application_delivery_controller>= 13.1, < 13.1-51.15
citrixnetscaler_application_delivery_controller>= 14.1, < 14.1-12.35
citrixnetscaler_gateway>= 13.0, < 13.0-92.21
citrixnetscaler_gateway>= 13.1, < 13.1-51.15
citrixnetscaler_gateway>= 14.1, < 14.1-12.35

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-6548