Vulnerability record · CVE-2023-6548 · published 17 January 2024
CVE-2023-6548: Citrix NetScaler ADC and Gateway code injection enables low-privileged RCE
Citrix · Netscaler Application Delivery Controller
NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management interface execute code remotely. The attacker must already hold low-privileged credentials, but no user interaction is required and the impact on confidentiality, integrity and availability is high. Because these appliances often sit at the network edge, a foothold there is valuable to an intruder.
Description
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with confirmed in-the-wild exploitation and a high CVSS of 8.8, though it requires low-privileged credentials to reach.
What it is
NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management interface execute code remotely. The attacker must already hold low-privileged credentials, but no user interaction is required and the impact on confidentiality, integrity and availability is high. Because these appliances often sit at the network edge, a foothold there is valuable to an intruder.
Impact
An authenticated low-privileged attacker gains remote code execution on the management interface, giving control over the appliance and the traffic and credentials it handles. That can lead to full compromise of the device and any trust relationships it holds.
Attack surface
Reached over the network via the management interface on an NSIP, CLIP or SNIP address; the vector is AV:N/AC:L/PR:L/UI:N, so valid low-privileged credentials are required and no user interaction is needed.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2024-01-17 with a remediation due date of 2024-01-24, indicating exploitation in the wild; EPSS gives a 30-day probability of about 3.2 percent (87th percentile). No ransomware campaign use is recorded.
What to do
- Apply the vendor patch from the Citrix security bulletin CTX584986 for CVE-2023-6548 and CVE-2023-6549 as the first action.
- If patching cannot be done immediately, follow Citrix mitigation guidance or discontinue use of the affected appliance, per CISA's required action.
- Restrict network access to NSIP, CLIP and SNIP management interfaces to trusted administrative networks only.
- Review and reduce management-interface accounts to the minimum needed, and rotate credentials for any account that could reach those interfaces.
- Monitor for and remove unauthorized accounts or configuration changes on the appliance after patching.
Detection
- Audit authentication logs on NetScaler management interfaces for logins from unexpected source addresses or at unusual times.
- Look for unexpected processes, scripts or configuration changes on the appliance that follow a management-interface login.
- Alert on management-interface access from outside approved administrative network ranges.
- Correlate NetScaler management logins with downstream lateral movement or credential use in other systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-6548 to the Known Exploited Vulnerabilities catalog on 17 January 2024 as "Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 January 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-6548 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6548), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.