CVE-2023-3519
CRITICAL KEV RANSOMWARE NUCLEIUnspecified Product <Version> - RCE
Title source: llmDescription
Unauthenticated remote code execution
Exploits (17)
nomisec
SCANNER
66 stars
by mandiant · poc
https://github.com/mandiant/citrix-ioc-scanner-cve-2023-3519
nomisec
SCANNER
53 stars
by telekom-security · poc
https://github.com/telekom-security/cve-2023-3519-citrix-scanner
metasploit
WORKING POC
NORMAL
by Ron Bowes, Douglass McKee, Spencer McIntyre, rwincey · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/freebsd/http/citrix_formssso_target_rce.rb
Nuclei Templates (1)
Citrix NetScaler ADC and NetScaler Gateway - Remote Code Execution
CRITICALby pussycat0x,ritikchaddha
Shodan:
http.title:"citrix gateway" || title:"netscaler gateway"
FOFA:
title="netscaler aaa" || title="citrix gateway" || title:"netscaler gateway"
References (3)
Scores
CVSS v3
9.8
EPSS
0.9394
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2023-07-19
VulnCheck KEV
2023-07-18
InTheWild.io
2023-07-19
ENISA EUVD
EUVD-2023-44176
Ransomware Use
Confirmed
CWE
CWE-94
Status
published
Products (3)
citrix/netscaler_application_delivery_controller
12.1 - 12.1-55.297 (2 CPE variants)
citrix/netscaler_application_delivery_controller
13.0 - 13.0-91.13
citrix/netscaler_gateway
13.0 - 13.0-91.13
Published
Jul 19, 2023
KEV Added
Jul 19, 2023
Tracked Since
Feb 18, 2026