CVE-2023-6548
CVE Published | 2024-01-17 |
---|---|
Related CWE(s) | CWE-94: Improper Control of Generation of Code ('Code Injection') |
Related Vendor(s) | citrix |
Related Product(s) | netscaler_gateway, netscaler_application_delivery_controller |
Exploitation Reported (CISA KEV) | 2024-01-17 |
CVSS 3 Base Score | 5.5 (MEDIUM) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | ADJACENT_NETWORK |
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph