CVE-2023-6548

EUVD-2023-58778
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CitrixCNA
5.5 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
citrixnetscaler_application_delivery_controller
13.0 ≤
𝑥
< 13.0-92.21
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-37.176
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-51.15
citrixnetscaler_application_delivery_controller
14.1 ≤
𝑥
< 14.1-12.35
citrixnetscaler_gateway
13.0 ≤
𝑥
< 13.0-92.21
citrixnetscaler_gateway
13.1 ≤
𝑥
< 13.1-51.15
citrixnetscaler_gateway
14.1 ≤
𝑥
< 14.1-12.35
𝑥
= Vulnerable software versions