January 17, 2024 · Applied Cybernetics Group
CVE-2023-6548 — Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
- Added to KEV
2024-01-17- Federal due date
2024-01-24- Vendor
- Citrix
- Product
- NetScaler ADC and NetScaler Gateway
- EPSS
- 91.3th percentile (score 0.065, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-6548
CISA short description
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.