Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 57.6%; technical severity is CVSS 7.5.
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Who should care
- Teams operating NetScaler ADC and NetScaler Gateway, Netscaler Application Delivery Controller, Netscaler Gateway
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether NetScaler ADC and NetScaler Gateway, Netscaler Application Delivery Controller, Netscaler Gateway is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Citrix Security advisory
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-119
- Affected versions
- Citrix NetScaler ADC and NetScaler Gateway; Citrix Netscaler Application Delivery Controller (Start Including 12.1, End Excluding 12.1-55.302 | Start Including 12.1, End Excluding 12.1-55.302 | Start Including 13.0, End Excluding 13.0-92.21 | Start Including 13.1, End Excluding 13.1-37.176); Citrix Netscaler Gateway (Start Including 13.0, End Excluding 13.0-92.21 | Start Including 13.1, End Excluding 13.1-51.15 | Start Including 14.1, End Excluding 14.1-12.35)
- Fixed versions
- Citrix Netscaler Application Delivery Controller (Fixed from 12.1-55.302, 13.0-92.21, 13.1-37.176, 13.1-51.15, 14.1-12.35); Citrix Netscaler Gateway (Fixed from 13.0-92.21, 13.1-51.15, 14.1-12.35)
- Published
- 17 January 2024
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 57.6%
- Signal calculated at 78