CVE-2023-3519 is a critical unauthenticated remote code execution vulnerability affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway products. This flaw allows attackers to execute arbitrary code without authentication, posing a severe risk to affected systems. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including by ransomware campaigns, and public exploit modules are available, leading to significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-55.297CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 12.1, < 12.1-55.297CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* | ||
>= 13.0, < 13.0-91.13CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* | ||
>= 13.1, < 13.1-37.159CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 13.1, < 13.1-49.13CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.