← Back to browse · API

CVE-2023-6548

Severity
MEDIUM
CVSS
5.5
EPSS
0.03191
Risk score
48.12
CISA KEV
Yes
PoC
No
Published
2024-01-17
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-58778, GHSA-W4RW-V3MM-HJ8H
Products
Citrix:NetScaler ADC 12.1-FIPS <55.302, Citrix:NetScaler ADC 12.1-NDcPP <55.302, Citrix:NetScaler ADC 13.0 <92.21, Citrix:NetScaler ADC 13.1 <51.15, Citrix:NetScaler ADC 13.1-FIPS <37.176, Citrix:NetScaler ADC 14.1 <12.35, Citrix:NetScaler ADC and NetScaler Gateway, Cloud Software Group:NetScaler Gateway 13.0 <92.21, Cloud Software Group:NetScaler Gateway 13.1 <51.15, Cloud Software Group:NetScaler Gateway 14.1 <12.35
Sources
euvd EUVD-2023-58778
cisa.gov CVE-2023-6548

Description

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

References