CVE-2023-6549 is a critical vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway, stemming from an improper restriction of operations within a memory buffer. This flaw allows for unauthenticated denial of service and out-of-bounds memory reads. With a CVSS score of 7.5 (High), it can be exploited remotely with low complexity, leading to significant availability impacts. This CVE is actively exploited in the wild, as indicated by its presence in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, including a Nuclei template for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.1-FIPS, < 37.176CPE match | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:*:*:*:* | ||
>= 13.1, < 51.15CPE match | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:*:*:*:* | ||
>= 12.1-FIPS, < 55.302CPE match | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:*:*:*:* | ||
>= 12.1-NDcPP, < 55.302CPE match | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:*:*:*:* | ||
>= 13.0, < 92.21CPE match | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.