Skip to content
COOEY

EXPOSURES › CVE-2023-6549

CVE-2023-6549

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-6549 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedransomware

Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild.

This buffer overflow flaw in Citrix NetScaler ADC and Gateway products enables denial-of-service attacks on critical VPN and AAA virtual servers, posing a significant risk to DIB organizations relying on these appliances for secure access. Because the vulnerability is actively exploited in the wild and linked to ransomware campaigns, DIB orgs must immediately patch and verify their NetScaler deployments to prevent service disruption and potential lateral movement.

Shame score — While the vulnerability is actively exploited and linked to ransomware, it is a known buffer overflow that allows denial-of-service rather than remote code execution, resulting in moderate embarrassment compared to RCE or data breach failures.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized