Page 1 of 1

Citrix warns of new Netscaler zero-days exploited in attacks

Posted: Wed Jan 17, 2024 12:39 pm
by rbc
Citrix urged customers on Tuesday to immediately patch Netscaler ADC and Gateway appliances exposed online against two actively exploited zero-day vulnerabilities.

The two zero-days (tracked as CVE-2023-6548 and CVE-2023-6549) impact the Netscaler management interface and expose unpatched Netscaler instances to remote code execution and denial-of-service attacks, respectively.

However, to gain code execution, attackers must be logged in to low-privilege accounts on the targeted instance and need access to NSIP, CLIP, or SNIP with management interface access.
[...]
Citrix warns of new Netscaler zero-days exploited in attacks