Vulnerability Intelligence Report
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CVE-2023-6548
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
5.5
MEDIUM
Exploitability:2.1
Impact Score:3.4
EPSS Probability:3.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Cloud Software Group | NetScaler ADC | 14.1 < 12.35 (affected), 13.1 < 51.15 (affected), 13.0 < 92.21 (affected), 13.1-FIPS < 37.176 (affected), 12.1-FIPS < 55.302 (affected), 12.1-NDcPP < 55.302 (affected) |
| Cloud Software Group | NetScaler Gateway | 14.1 < 12.35 (affected), 13.1 < 51.15 (affected), 13.0 < 92.21 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Citrix Systems, Inc. · Vendor · USA |
| Reserved | 2023-12-06T11:01:54 |
| Published | 2024-01-17T20:11:18 |
| Last Updated | 2025-10-21T23:05:28 |
Community Chatter & Buzz