Nynox advisory - Threat alert -
Citrix Netscaler ADC / Gateway
– Date: 16 January 2024 –
Threat Alert – Citrix Netscaler ADC / Gateway Multiple Vulnerabilities – Your environment might be vulnerable to multiple Citrix Netscaler ADC and Gateway vulnerabilities (CVE-2023-6548 , CVE-2023-6549). Read more below for details on the recent critical vulnerabilities.
On the 16th of January, Citrix has put out communication regarding two products who are vulnerable towards a critical zero-day vulnerability, A Denial of Service and Remote Code Execution.
What’s going on?
❗️Several critical risk vulnerabilities have been published by Citrix in Netscaler ADC and Gateway.
❗️For a Citrix Netscaler ADC and Gateway to be vulnerable, it must be configured as a Gateway (e.g. VPN, ICA Proxy, CVP, RDP Proxy) or an AAA virtual server.
❗️The affected versions for both products are:
- 14.1 before 14.1-12.35
- 13.1 before 13.1-51.15
- 13.0 before 13.0-92.21
- 13.1-FIPS before 13.1-37.176
- 12.1-FIPS before 12.1-55.302
- 12.1-NDcPP before 12.1-55.302
