CVE-2023-6548 is a critical code injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway products. It allows an authenticated, low-privileged attacker with management interface access (via NSIP, CLIP, or SNIP) to achieve remote code execution. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. Notably, this CVE is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-55.302CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 12.1, < 12.1-55.302CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* | ||
>= 13.0, < 13.0-92.21CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* | ||
>= 13.1, < 13.1-37.176CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 13.1, < 13.1-51.15CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.