{
  "id": "CVE-2023-6548",
  "url": "https://spydr.io/cve/CVE-2023-6548",
  "published": "2024-01-17T20:15:50.627Z",
  "modified": "2026-06-17T06:50:58.003Z",
  "score": 8.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.03191,
  "epss_percentile": 0.87693,
  "exploited": true,
  "kev": {
    "added": "2024-01-17",
    "due": "2024-01-24",
    "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
    "ransomware": "Unknown",
    "name": "Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
    "notes": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549; https://nvd.nist.gov/vuln/detail/CVE-2023-6548"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Cloud Software Group",
    "citrix"
  ],
  "products": [
    "Cloud Software Group NetScaler ADC",
    "Cloud Software Group NetScaler Gateway",
    "citrix netscaler_application_delivery_controller",
    "citrix netscaler_gateway"
  ],
  "cwes": [
    "CWE-94"
  ],
  "description": "Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 8.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6548",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
