CVE-2023-6548
KEVlargeAuthenticated Code-Injection RCE in Citrix NetScaler ADC/Gateway
CISA: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CVE-2023-6548 is a code injection flaw (CWE-94) in the management interface of Citrix NetScaler ADC and NetScaler Gateway that allows remote code execution. It is triggered when an attacker who can reach the appliance's NSIP, CLIP, or a SNIP with management interface access authenticates with valid low-privileged credentials and sends crafted input that the appliance turns into executable code. Successful exploitation yields authenticated remote code execution in the context of the management interface, with high impact on the confidentiality, integrity, and availability of the appliance. Affected organizations are those running Citrix NetScaler ADC or NetScaler Gateway appliances, particularly deployments whose management interfaces are reachable from less-trusted networks or shared with low-privileged users. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17 and urged immediate action, though no public proof-of-concept code is known and EPSS currently estimates a ~3.2% chance of exploitation within 30 days.
What to do: Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the fixed builds in Citrix's security bulletin for CVE-2023-6548 (released alongside the companion CVE-2023-6546 NetScaler privilege-escalation fix), per CISA's KEV directive to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Reduce exposure by restricting management interface access on the NSIP, CLIP, and SNIPs to trusted admin networks and by removing or constraining low-privileged accounts that do not need management access. Review appliance authentication logs and configurations for unexpected logins or changes, since exploitation requires authenticated access to the management interface.
| Citrix NetScaler Application Delivery Controller (ADC) | — |
| Citrix NetScaler Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
- Affected
- Citrix NetScaler ADC and NetScaler Gateway
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- netscaler application delivery controller, netscaler gateway
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H