HIGH

CVE-2023-6548

Citrix Netscaler Application Delivery Controller 2024-01-17 CVSS v3.1
CVSS
8.8
KEV

Description

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

Summary dbcve.org

Code injection vulnerability in NetScaler ADC and NetScaler Gateway allowing authenticated low-privileged users to achieve remote code execution on the management interface via NSIP, CLIP, or SNIP access.

Mitigation

Restrict network access to management interfaces (NSIP, CLIP, SNIP) to trusted networks only and apply vendor patches when available; implement network segmentation and least-privilege access controls.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

3.19%
Probability of exploitation in next 30 days
87.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE