ZeroHour

CVE-2023-6548

KEVlarge

Authenticated Code-Injection RCE in Citrix NetScaler ADC/Gateway

CISA: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2023-6548 is a code injection flaw (CWE-94) in the management interface of Citrix NetScaler ADC and NetScaler Gateway that allows remote code execution. It is triggered when an attacker who can reach the appliance's NSIP, CLIP, or a SNIP with management interface access authenticates with valid low-privileged credentials and sends crafted input that the appliance turns into executable code. Successful exploitation yields authenticated remote code execution in the context of the management interface, with high impact on the confidentiality, integrity, and availability of the appliance. Affected organizations are those running Citrix NetScaler ADC or NetScaler Gateway appliances, particularly deployments whose management interfaces are reachable from less-trusted networks or shared with low-privileged users. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17 and urged immediate action, though no public proof-of-concept code is known and EPSS currently estimates a ~3.2% chance of exploitation within 30 days.

What to do: Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the fixed builds in Citrix's security bulletin for CVE-2023-6548 (released alongside the companion CVE-2023-6546 NetScaler privilege-escalation fix), per CISA's KEV directive to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Reduce exposure by restricting management interface access on the NSIP, CLIP, and SNIPs to trusted admin networks and by removing or constraining low-privileged accounts that do not need management access. Review appliance authentication logs and configurations for unexpected logins or changes, since exploitation requires authenticated access to the management interface.

Affected
Citrix NetScaler Application Delivery Controller (ADC)
Citrix NetScaler Gateway
Estimated exposure
large~tens of thousands of NetScaler appliances with reachable management interfaces (out of a very large global installed base) — Citrix NetScaler ADC/Gateway has a very large installed base and public internet-wide scans have historically shown tens of thousands of Citrix NetScaler devices exposed online, but this flaw additionally requires access to the management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CISA Known Exploited Vulnerability
Affected
Citrix NetScaler ADC and NetScaler Gateway
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
netscaler application delivery controller, netscaler gateway
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news