CVE-2023-6548

EUVD-2023-58778
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
citrixnetscaler_application_delivery_controller
13.0 ≤
𝑥
< 13.0-92.21
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-37.176
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-51.15
citrixnetscaler_application_delivery_controller
14.1 ≤
𝑥
< 14.1-12.35
citrixnetscaler_gateway
13.0 ≤
𝑥
< 13.0-92.21
citrixnetscaler_gateway
13.1 ≤
𝑥
< 13.1-51.15
citrixnetscaler_gateway
14.1 ≤
𝑥
< 14.1-12.35
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
citrixnetscaler_application_delivery_controller
14.1 ≤
𝑥
< 14.1-12.35
ADP
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-51.15
ADP
citrixnetscaler_application_delivery_controller
13.0 ≤
𝑥
< 13.0-92.21
ADP
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-37.176
ADP
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
ADP
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
ADP
citrixnetscaler_gateway
14.1 ≤
𝑥
< 14.1-12.35
ADP
citrixnetscaler_gateway
13.1 ≤
𝑥
< 13.1-51.15
ADP
citrixnetscaler_gateway
13.0 ≤
𝑥
< 13.0-92.21
ADP