• News/
  • https://www.theregister.com/2024/01/18/citrix_netscaler_bugs_attacked/

Two more Citrix NetScaler bugs exploited in the wild

The Register
·
Jessica Lyons Hardcastle
·
Published Jan 18, 2024
·
Updated

Two vulnerabilities in NetScaler's ADC and Gateway products have been fixed – but not before criminals found and exploited them, according to the vendor. CVE-2023-6548 could allow remote code execution (RCE) in the appliances' management interface. It received a 5.5 CVSS rating, which is low for an RCE bug. One reason for this may be because it does require the attacker to be authenticated, albeit with low-level privileges, and they must have access to NetScaler IP (NSIP), Subnet IP (SNIP), or cluster management IP (CLIP) with management interface access. In addition, this vulnerability cannot be exploited if the management console and related tech is not configured with exposure to the public internet, and NetScaler's configuration instructions recommend that it only be configured on a private network. TLDR: If you followed Citrix's instructions, your appliances should be safe. The bad news? According to Shadowserver, just over 1,400 Netscaler management interfaces are exposed on the internet as of Wednesday afternoon. The second bug, tracked as CVE-2023-6549, could allow a denial-of-service attack, and earned an 8.2 CVSS rating. A successful exploit requires the appliance be configured as a gateway (such as a VPN virtual server, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server that provides authentication, authorization, and accounting controls. "Exploits of these CVEs on unmitigated appliances have been observed," according to a Tuesday security alert from Citrix....

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of two vulnerabilities in Citrix NetScaler products, specifically affecting the ADC and Gateway.

2

What security implications are discussed in the article?

The vulnerabilities could allow remote code execution, posing significant risks to organizations using these Citrix products.

3

What products from Citrix are affected by the vulnerabilities?

The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.

4

Were these vulnerabilities exploited before being patched?

Yes, criminals exploited the vulnerabilities before Citrix applied the necessary patches.

5

What are the CVE identifiers associated with the vulnerabilities?

The vulnerabilities are identified as CVE-2023-6548.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203