CVE-2023-3467: High severity Citrix NetScaler Application Delivery Controller vulnerability
Published Jul 19, 2023
·Updated
Privilege Escalation to root administrator (nsroot)
Affected Software
8 affected components
Citrix NetScaler Application Delivery Controller>=12.1<12.1-55.297
Citrix NetScaler Application Delivery Controller>=12.1<12.1-55.297
Citrix NetScaler Application Delivery Controller>=13.0<13.0-91.13
Citrix NetScaler Application Delivery Controller>=13.1<13.1-37.159
Citrix NetScaler Application Delivery Controller>=13.1<13.1-49.13
Citrix NetScaler Application Delivery Controller=11.1-65.22
Citrix NetScaler Gateway>=13.0<13.0-91.13
Citrix NetScaler Gateway>=13.1<13.1-49.13
Event History
Jul 19, 2023
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Data Sourced
07:15 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-3467?
CVE-2023-3467 is a vulnerability that allows privilege escalation to root administrator (nsroot) on Citrix Netscaler Application Delivery Controller and Citrix Netscaler Gateway.
2
How severe is CVE-2023-3467?
CVE-2023-3467 has a severity value of 8, which is considered high.
3
Which software is affected by CVE-2023-3467?
Citrix Netscaler Application Delivery Controller and Citrix Netscaler Gateway versions between 12.1-55.297 and 13.1-49.13 are affected by CVE-2023-3467.
4
How do I fix CVE-2023-3467?
To fix CVE-2023-3467, Citrix has released security updates. Please refer to the following reference for more information: [link](https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467)
5
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-3467?
The CWE ID of CVE-2023-3467 is 269.