HIGH KEV
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Published Jan 17, 2024 ·Due Feb 7, 2024
8.2
HIGHCVSS 3.1
EPSS 57.63%
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Affected products
-
- Version 12.1-FIPSStatusaffectedConstraints<55.302
- Version 12.1-NDcPPStatusaffectedConstraints<55.302
- Version 13.0StatusaffectedConstraints<92.21
- Version 13.1StatusaffectedConstraints<51.15
- Version 13.1-FIPSStatusaffectedConstraints<37.176
- Version 14.1StatusaffectedConstraints<12.35
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cloud Software Group | NetScaler ADC | unaffected |
|
OR
- ≥ 12.1 · < 12.1-55.302
- ≥ 12.1 · < 12.1-55.302
- ≥ 13.0 · < 13.0-92.21
- ≥ 13.1 · < 13.1-37.176
- ≥ 13.1 · < 13.1-51.15
- ≥ 14.1 · < 14.1-12.35
- ≥ 13.0 · < 13.0-92.21
- ≥ 13.1 · < 13.1-51.15
- ≥ 14.1 · < 14.1-12.35
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58779 Advisory
- https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6549 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58779 | Advisory | |
| https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549 | Vendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6549 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Citrix
Published Jan 17, 2024
Updated Oct 21, 2025
Reserved Dec 6, 2023
Link CVE-2023-6549
CISA Vulnrichment
Updated Jan 31, 2024
ENISA EUVD
EUVD-2023-58779 Assigner Citrix
Published Jan 17, 2024
Updated Oct 21, 2025
Exploited since Jan 17, 2024
Link EUVD-2023-58779