Skip to content
COOEY

EXPOSURES › CVE-2023-6548

CVE-2023-6548

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-6548 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildransomwareunpatched

Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild.

This vulnerability enables authenticated remote code execution on the management interface of Citrix NetScaler ADC and Gateway devices, exposing critical infrastructure to compromise. DIB organizations must immediately patch NetScaler deployments to prevent unauthorized access to NSIP, CLIP, or SNIP, which could lead to data exfiltration or lateral movement. The fact that this is actively exploited in the wild underscores the urgency of remediation.

Shame score — Active exploitation in the wild with authenticated RCE on management interfaces indicates a high-risk, avoidable failure that could compromise sensitive data and compliance posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized