CVE-2023-6549: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Other sources
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If vendor mitigations are unavailable, discontinue use of Citrix NetScaler ADC and Citrix NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6549?
CVE-2023-6549 is classified as a high severity vulnerability due to its potential to cause denial-of-service.
How do I fix CVE-2023-6549?
To mitigate CVE-2023-6549, it's essential to apply the latest patches provided by Citrix for affected NetScaler ADC and Gateway versions.
What systems are affected by CVE-2023-6549?
CVE-2023-6549 affects Citrix NetScaler ADC, NetScaler Gateway, and specific versions of Citrix's Application Delivery Controller.
What type of vulnerability is CVE-2023-6549?
CVE-2023-6549 is a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway or AAA virtual server.
Can CVE-2023-6549 be exploited remotely?
Yes, CVE-2023-6549 can be exploited remotely if the affected configurations are exposed to the internet.