CVE-2023-6548

CVE Published 2024-01-17
Related CWE(s) CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) citrix
Related Product(s) netscaler_gateway, netscaler_application_delivery_controller
Exploitation Reported (CISA KEV) 2024-01-17
CVSS 3 Base Score 5.5 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector ADJACENT_NETWORK

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References