CVE-2023-6549
KEVlargeUnauthenticated Buffer Overflow DoS and Memory Leak in Citrix NetScaler ADC/Gateway
CISA: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
CVE-2023-6549 is a buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway in which operations are not properly restricted to the bounds of a memory buffer. An unauthenticated remote attacker can trigger the flaw by sending network requests to an affected device, causing the appliance to crash or read data beyond the buffer's bounds. The attacker gains denial of service against the appliance plus potential disclosure of memory contents through the out-of-bounds read; the CVSS vector (7.5 High) scores high availability impact with no confidentiality or integrity impact. Any organization running an affected Citrix NetScaler ADC or NetScaler Gateway appliance reachable over the network is affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17 alongside a related NetScaler flaw, and EPSS assigns a 57.6% probability of exploitation within 30 days.
What to do: Apply the fixed builds per Citrix's advisory immediately (required by CISA's KEV catalog) and verify the upgrade on all ADC and Gateway appliances. Since the flaw is unauthenticated and remotely triggerable, also restrict network access to affected NetScaler interfaces until patched and monitor appliances for unexplained crashes or anomalous responses. Check vendor guidance for the exact version/build ranges in your deployment, as the source data does not specify fixed versions.
| Citrix NetScaler ADC (Application Delivery Controller) | — |
| Citrix NetScaler Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
- Affected
- Citrix NetScaler ADC and NetScaler Gateway
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- netscaler application delivery controller, netscaler gateway
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H