First published: Wed Jan 17 2024(Updated: )
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Credit: secure@citrix.com secure@citrix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler | ||
Citrix NetScaler SD-WAN | ||
Google Chrome | ||
Citrix NetScaler ADC | >=12.1<12.1-55.302 | |
Citrix NetScaler ADC | >=12.1<12.1-55.302 | |
Citrix NetScaler ADC | >=13.0<13.0-92.21 | |
Citrix NetScaler ADC | >=13.1<13.1-37.176 | |
Citrix NetScaler ADC | >=13.1<13.1-51.15 | |
Citrix NetScaler ADC | >=14.1<14.1-12.35 | |
Citrix Netscaler Gateway Firmware | >=13.0<13.0-92.21 | |
Citrix Netscaler Gateway Firmware | >=13.1<13.1-51.15 | |
Citrix Netscaler Gateway Firmware | >=14.1<14.1-12.35 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6549 is classified as a high severity vulnerability due to its potential to cause denial-of-service.
To mitigate CVE-2023-6549, it's essential to apply the latest patches provided by Citrix for affected NetScaler ADC and Gateway versions.
CVE-2023-6549 affects Citrix NetScaler ADC, NetScaler Gateway, and specific versions of Citrix's Application Delivery Controller.
CVE-2023-6549 is a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway or AAA virtual server.
Yes, CVE-2023-6549 can be exploited remotely if the affected configurations are exposed to the internet.