Technical Severity
MEDIUMCVSS v3.1 Metrics
5.5
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitation Likelihood
EPSS Prediction
8.30
%
Predictive Probability
Percentile Rank
92.2
th
Documented as more likely to be exploited than 92.2% of known CVEs.
Detection Date
Jan 17, 2024
Remediation Due
Jan 24, 2024
CISA Catalog Active
Threat Analysis
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549
https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549
NVD
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2023-6548