CISA Known Exploited Vulnerability (KEV)
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
January 17, 2024
January 24, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Improper Control of Generation of Code (‘Code Injection’) in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-94 |
Improper Control of Generation of Code (‘Code Injection’) |