Skip to content
COOEY

EXPOSURES › CVE-2023-3519

CVE-2023-3519

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-07-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-3519 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks.

The unauthenticated remote code execution flaw allowed attackers to inject and execute arbitrary code on Citrix NetScaler ADC and Gateway systems without needing credentials. This failure is critical for DIB organizations because it directly enables ransomware deployment and violates CMMC/NIST 800-171 requirements for patching known vulnerabilities and preventing unauthorized access. Organizations must ensure all Citrix NetScaler instances are patched immediately and monitored for signs of exploitation.

Shame score — The vulnerability was unauthenticated, actively exploited in the wild, and directly linked to ransomware, representing a severe, avoidable failure in Citrix's security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized