EXPOSURES › CVE-2023-6548
CVE-2023-6548
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild.
This vulnerability enables authenticated remote code execution on the management interface of Citrix NetScaler ADC and Gateway devices, exposing critical infrastructure to compromise. DIB organizations must immediately patch NetScaler deployments to prevent unauthorized access to NSIP, CLIP, or SNIP, which could lead to data exfiltration or lateral movement. The fact that this is actively exploited in the wild underscores the urgency of remediation.
Shame score — Active exploitation in the wild with authenticated RCE on management interfaces indicates a high-risk, avoidable failure that could compromise sensitive data and compliance posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |