CVE-2023-6549
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Record summary
CVE-2023-6549 has a selected CVSS score of 8.2 (high); EIP currently links 1 Nuclei template. CISA lists CVE-2023-6549 in KEV.
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jan 17, 2024 · CISA
- VulnCheck KEV
- Listed · Jan 16, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NetScaler ADC and NetScaler GatewayBrowse Citrix / NetScaler ADC and NetScaler Gateway | CISA | Version data not supplied | |
NetScaler ADCBrowse Cloud Software Group / NetScaler ADCDefault status: unaffected | CVE List | 14.1 to < 12.35 | affected |
| 13.1 to < 51.15 | affected | ||
| 13.0 to < 92.21 | affected | ||
| 13.1-FIPS to < 37.176 | affected | ||
| 12.1-FIPS to < 55.302 | affected | ||
| 12.1-NDcPP to < 55.302 | affected | ||
Nuclei templates
1ProjectDiscoveryCRITICALCitrix Netscaler ADC & Gateway - Out-Of-Bounds Memory ReadCVSS 7.5
The vulnerability would enable an attacker to remotely obtain sensitive information from a NetScaler appliance configured as a Gateway or AAA virtual server via a very commonly connected Web interface, and without requiring authentication. This bug is nearly identical to the Citrix Bleed vulnerability (CVE-2023-4966), except it is less likely to return highly sensitive information to an attacker.
Impact
The vulnerability allows an attacker to recover potentially sensitive data from memory. Although in most cases nothing of value is returned, we have observed instances where POST request bodies are leaked.
Remediation
Update to version 13.1-51.15 or later
Source: ProjectDiscovery