← Vulnerability feed

Vulnerability record · CVE-2023-6549 · published 17 January 2024

CVE-2023-6549: Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoS

Citrix · Netscaler Application Delivery Controller

NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-bounds memory read and denial of service. The flaw is remotely reachable without authentication, and Citrix has issued a vendor advisory covering this CVE alongside CVE-2023-6548. Because these appliances commonly sit at the network edge, unauthenticated availability impact is significant.

7.5 CVSS 3.1 High CISA KEV since 17 Jan 2024 EPSS 58% · top 0.9% CWE-119 · Memory buffer overflow
7.5CVSS 3.1 base score
58%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is unauthenticated, network-reachable, causes availability impact, and is listed in CISA KEV with high EPSS, though it is rated 7.5 HIGH rather than critical.

What it is

NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-bounds memory read and denial of service. The flaw is remotely reachable without authentication, and Citrix has issued a vendor advisory covering this CVE alongside CVE-2023-6548. Because these appliances commonly sit at the network edge, unauthenticated availability impact is significant.

Impact

An unauthenticated attacker can trigger an out-of-bounds memory read and cause a denial of service, disrupting availability of the NetScaler appliance and any services it fronts. The record does not state whether the memory read can be leveraged for information disclosure beyond the DoS.

Attack surface

Reached over the network via the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not specify which interface or endpoint is targeted, so the exact reachable path is not detailed in this record.

Exploitation

CVE-2023-6549 is listed in CISA KEV with a due date of 2024-02-07, indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.57633 (99th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the vendor patch per the Citrix security bulletin CTX584986 for CVE-2023-6548 and CVE-2023-6549.
  • If patching is not immediately possible, apply the mitigations in the vendor instructions or discontinue use of the affected appliance as directed by CISA KEV.
  • Restrict management and service exposure of NetScaler ADC and Gateway to trusted networks where feasible.
  • Monitor vendor advisories for updated guidance, since the bulletin covers two CVEs.
  • Verify patch level on all NetScaler ADC and Gateway instances, including HA pairs and disaster recovery nodes.

Detection

  • Monitor NetScaler appliance logs and system events for unexpected crashes, restarts or service interruptions.
  • Watch for anomalous or malformed traffic patterns toward NetScaler ADC and Gateway endpoints that precede availability loss.
  • Alert on NetScaler process restarts or failover events that correlate with external connection bursts.
  • Track CISA KEV status and vendor bulletin updates to confirm exposure and remediation state.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-6549 to the Known Exploited Vulnerabilities catalog on 17 January 2024 as "Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 February 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-6549 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed

Source: NIST National Vulnerability Database (record CVE-2023-6549), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.