CVE-2023-6548

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gatewayallows an attacker withaccessto NSIP, CLIP or SNIP with management interface to performAuthenticated (low privileged) remote code execution on Management Interface.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CitrixCNA
5.5 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
citrixnetscaler_application_delivery_controller
12.1 ≤
𝑥
< 12.1-55.302
citrixnetscaler_application_delivery_controller
13.0 ≤
𝑥
< 13.0-92.21
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-37.176
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-51.15
citrixnetscaler_application_delivery_controller
14.1 ≤
𝑥
< 14.1-12.35
citrixnetscaler_gateway
13.0 ≤
𝑥
< 13.0-92.21
citrixnetscaler_gateway
13.1 ≤
𝑥
< 13.1-51.15
citrixnetscaler_gateway
14.1 ≤
𝑥
< 14.1-12.35
𝑥
= Vulnerable software versions