Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2023-6549
Published: January 16, 2024 / Updated: January 17, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote attacker can send specially crated packets to the system, trigger memory corruption and perform a denial of service (DoS) attack.
Successful exploitation of this vulnerability requires that the device is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAAvirtualserver.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2023-6549
Citrix NetScaler Gateway - addressed in versions 13.0-92.21, 13.1-51.15, 14.1-12.35