Two vulnerabilities in NetScaler's ADC and Gateway products have been fixed – but not before criminals found and exploited them, according to the vendor. CVE-2023-6548 could allow remote code execution (RCE) in the appliances' management interface. It received a 5.5 CVSS rating, which is low for an RCE bug. One reason for this may be because it does require the attacker to be authenticated, albeit with low-level privileges, and they must have access to NetScaler IP (NSIP), Subnet IP (SNIP), or cluster management IP (CLIP) with management interface access. In addition, this vulnerability cannot be exploited if the management console and related tech is not configured with exposure to the public internet, and NetScaler's configuration instructions recommend that it only be configured on a private network. TLDR: If you followed Citrix's instructions, your appliances should be safe. The bad news? According to Shadowserver, just over 1,400 Netscaler management interfaces are exposed on the internet as of Wednesday afternoon. The second bug, tracked as CVE-2023-6549, could allow a denial-of-service attack, and earned an 8.2 CVSS rating. A successful exploit requires the appliance be configured as a gateway (such as a VPN virtual server, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server that provides authentication, authorization, and accounting controls. "Exploits of these CVEs on unmitigated appliances have been observed," according to a Tuesday security alert from Citrix....
Two more Citrix NetScaler bugs exploited in the wild
The Register
·Jessica Lyons Hardcastle
·Published Jan 18, 2024
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of two vulnerabilities in Citrix NetScaler products, specifically affecting the ADC and Gateway.
2
What security implications are discussed in the article?
The vulnerabilities could allow remote code execution, posing significant risks to organizations using these Citrix products.
3
What products from Citrix are affected by the vulnerabilities?
The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.
4
Were these vulnerabilities exploited before being patched?
Yes, criminals exploited the vulnerabilities before Citrix applied the necessary patches.
5
What are the CVE identifiers associated with the vulnerabilities?
The vulnerabilities are identified as CVE-2023-6548.