Improper access control in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2023-3467
Published: July 19, 2023
Vulnerability identifier: #VU78375
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3467
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions to NSIP and SNIP features. A remote user with access to management interface can bypass implemented security restrictions and gain nsroot privileges
Affected software
Citrix Netscaler ADC
Citrix NetScaler Gateway
Citrix NetScaler Gateway
How to mitigate CVE-2023-3467
Install updates from vendor's website.
Citrix Netscaler ADC - addressed in versions 12.1-55.297, 13.0.91.13, 13.1-37.159, 13.1-49.13
Citrix NetScaler Gateway - addressed in versions 13.0.91.13, 13.1.49.13
Citrix NetScaler Gateway - addressed in versions 13.0.91.13, 13.1.49.13