Record summary

CVE-2023-6549 has a selected CVSS score of 8.2 (high); EIP currently links 1 Nuclei template. CISA lists CVE-2023-6549 in KEV.

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jan 17, 2024 · CISA
VulnCheck KEV
Listed · Jan 16, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

NetScaler ADC and NetScaler Gateway

Browse Citrix / NetScaler ADC and NetScaler Gateway
CISAVersion data not supplied

Default status: unaffected

CVE List14.1 to < 12.35affected
13.1 to < 51.15affected
13.0 to < 92.21affected
13.1-FIPS to < 37.176affected
12.1-FIPS to < 55.302affected
12.1-NDcPP to < 55.302affected

Nuclei templates

1
ProjectDiscoveryCRITICALCitrix Netscaler ADC & Gateway - Out-Of-Bounds Memory ReadCVSS 7.5

The vulnerability would enable an attacker to remotely obtain sensitive information from a NetScaler appliance configured as a Gateway or AAA virtual server via a very commonly connected Web interface, and without requiring authentication. This bug is nearly identical to the Citrix Bleed vulnerability (CVE-2023-4966), except it is less likely to return highly sensitive information to an attacker.

Impact

The vulnerability allows an attacker to recover potentially sensitive data from memory. Although in most cases nothing of value is returned, we have observed instances where POST request bodies are leaked.

Remediation

Update to version 13.1-51.15 or later

WeaknessesCWE-125
Authorsice3man
Template tagscvecve2023citrixnetscallergatewayoobkevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-1292923998,-1166125415

Source: ProjectDiscovery

References

3