Search

Find a vulnerability

Search criteria

    10 vulnerabilities by Cloud Software Group

    CVE-2023-6184 (GCVE-0-2023-6184)

    Vulnerability from nvd โ€“ Published: 2024-01-18 01:04 โ€“ Updated: 2025-06-02 15:04
    VLAI Previdian
    Summary
    Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-05-08 15:53 UTC
    CWE
    • CWE-913 - Improper Control of Dynamically-Managed Code Resources
    Impacted products
    Vendor Product Version
    Cloud Software Group Citrix Session Recording Affected: 2311 Current Release , < 0 (patch)
    Affected: 1912 LTSR , < CU8 hotfix 19.12.8100.4 (patch)
    Affected: 2203 LTSR , < CU4 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:21:17.772Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX583930/citrix-session-recording-security-bulletin-for-cve20236184"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-08T15:53:46.961310Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-02T15:04:27.473Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix Session Recording",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "0",
                  "status": "affected",
                  "version": "2311 Current Release",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU8 hotfix 19.12.8100.4",
                  "status": "affected",
                  "version": "1912 LTSR ",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU4",
                  "status": "affected",
                  "version": "2203 LTSR",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting"
                }
              ],
              "value": "Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-913",
                  "description": "CWE-913 Improper Control of Dynamically-Managed Code Resources",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-18T01:04:15.120Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX583930/citrix-session-recording-security-bulletin-for-cve20236184"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-6184",
        "datePublished": "2024-01-18T01:04:15.120Z",
        "dateReserved": "2023-11-16T21:18:24.367Z",
        "dateUpdated": "2025-06-02T15:04:27.473Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-6549 (GCVE-0-2023-6549)

    Vulnerability from nvd โ€“ Published: 2024-01-17 20:15 โ€“ Updated: 2025-10-21 23:05
    VLAI CISA Previdian
    Summary
    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service andย Out-Of-Bounds Memory Read
    SSVC
    Exploitation: active Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-31 05:00 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Cloud Software Group NetScaler ADC Affected: 14.1 , < 12.35 (patch)
    Affected: 13.1 , < 51.15 (patch)
    Affected: 13.0 , < 92.21 (patch)
    Affected: 13.1-FIPS , < 37.176 (patch)
    Affected: 12.1-FIPS , < 55.302 (patch)
    Affected: 12.1-NDcPP , < 55.302 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:35:13.934Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6549",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-31T05:00:20.477654Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-01-17",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6549"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:27.936Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6549"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-01-17T00:00:00.000Z",
                "value": "CVE-2023-6549 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler ADC",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "12.35",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "51.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.21",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "37.176",
                  "status": "affected",
                  "version": "13.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-NDcPP",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cb\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eImproper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and\u0026nbsp;\u003c/span\u003e\u003c/b\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cb\u003eOut-Of-Bounds Memory Read\u003c/b\u003e\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and\u00a0Out-Of-Bounds Memory Read"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-10T17:29:28.138Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-6549",
        "datePublished": "2024-01-17T20:15:53.345Z",
        "dateReserved": "2023-12-06T11:01:58.256Z",
        "dateUpdated": "2025-10-21T23:05:27.936Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5914 (GCVE-0-2023-5914)

    Vulnerability from nvd โ€“ Published: 2024-01-17 20:19 โ€“ Updated: 2025-06-17 21:19
    VLAI Previdian
    Summary
    Cross-site scripting (XSS)
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-18 01:07 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Cloud Software Group Citrix StoreFront Affected: 2308 Current Release , < 1 (patch)
    Affected: 2311 Current Release , < 0 (patch)
    Affected: 1912 LTSR , < CU8 hotfix 3.22.8001.2 (patch)
    Affected: 2203 LTSR , < CU4 Update 1 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:14:24.983Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX583759/citrix-storefront-security-bulletin-for-cve20235914"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5914",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-18T01:07:35.301720Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-17T21:19:18.814Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix StoreFront",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "1",
                  "status": "affected",
                  "version": "2308 Current Release",
                  "versionType": "patch"
                },
                {
                  "lessThan": "0",
                  "status": "affected",
                  "version": "2311 Current Release",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU8 hotfix 3.22.8001.2",
                  "status": "affected",
                  "version": "1912 LTSR",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU4 Update 1",
                  "status": "affected",
                  "version": "2203 LTSR ",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u0026nbsp; Cross-site scripting (XSS)"
                }
              ],
              "value": "\u00a0 Cross-site scripting (XSS)"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-17T20:19:49.869Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX583759/citrix-storefront-security-bulletin-for-cve20235914"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-5914",
        "datePublished": "2024-01-17T20:19:49.869Z",
        "dateReserved": "2023-11-01T22:55:27.290Z",
        "dateUpdated": "2025-06-17T21:19:18.814Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-6548 (GCVE-0-2023-6548)

    Vulnerability from nvd โ€“ Published: 2024-01-17 20:11 โ€“ Updated: 2025-10-21 23:05
    VLAI CISA Previdian
    Summary
    Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gatewayย allows an attacker withย accessย to NSIP, CLIP or SNIP with management interface to performย Authenticated (low privileged) remote code execution on Management Interface.
    SSVC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-18 14:00 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Cloud Software Group NetScaler ADC Affected: 14.1 , < 12.35 (patch)
    Affected: 13.1 , < 51.15 (patch)
    Affected: 13.0 , < 92.21 (patch)
    Affected: 13.1-FIPS , < 37.176 (patch)
    Affected: 12.1-FIPS , < 55.302 (patch)
    Affected: 12.1-NDcPP , < 55.302 (patch)
    Create a notification for this product.
    Cloud Software Group NetScaler Gateway Affected: 14.1 , < 12.35 (patch)
    Affected: 13.1 , < 51.15 (patch)
    Affected: 13.0 , < 92.21 (patch)
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 14.1 , < 14.1-12.35 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1:*:*:*:-:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 13.1 , < 13.1-51.15 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:-:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 13.0 , < 13.0-92.21 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0:*:*:*:-:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 13.1 , < 13.1-37.176 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:fips:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 12.1 , < 12.1-55.302 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:fips:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 12.1 , < 12.1-55.302 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:ndcpp:*:*:*
    Create a notification for this product.
    citrix netscaler_gateway Affected: 14.1 , < 14.1-12.35 (custom)
        cpe:2.3:a:citrix:netscaler_gateway:14.1:*:*:*:*:*:*:*
    Create a notification for this product.
    citrix netscaler_gateway Affected: 13.1 , < 13.1-51.15 (custom)
        cpe:2.3:a:citrix:netscaler_gateway:13.1:*:*:*:*:*:*:*
    Create a notification for this product.
    citrix netscaler_gateway Affected: 13.0 , < 13.0-92.21 (custom)
        cpe:2.3:a:citrix:netscaler_gateway:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "14.1-12.35",
                    "status": "affected",
                    "version": "14.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.1-51.15",
                    "status": "affected",
                    "version": "13.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.0-92.21",
                    "status": "affected",
                    "version": "13.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:fips:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.1-37.176",
                    "status": "affected",
                    "version": "13.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:fips:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "12.1-55.302",
                    "status": "affected",
                    "version": "12.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:ndcpp:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "12.1-55.302",
                    "status": "affected",
                    "version": "12.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_gateway:14.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_gateway",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "14.1-12.35",
                    "status": "affected",
                    "version": "14.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_gateway:13.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_gateway",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.1-51.15",
                    "status": "affected",
                    "version": "13.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_gateway:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_gateway",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.0-92.21",
                    "status": "affected",
                    "version": "13.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6548",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-18T14:00:57.375485Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-01-17",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:28.157Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-01-17T00:00:00.000Z",
                "value": "CVE-2023-6548 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:35:14.029Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler ADC",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "12.35",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "51.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.21",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "37.176",
                  "status": "affected",
                  "version": "13.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-NDcPP",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler Gateway",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "12.35",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "51.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.21",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eImproper Control of Generation of Code (\u0027Code Injection\u0027) in NetScaler ADC and NetScaler Gateway\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eallows an attacker with\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;access\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;to NSIP, CLIP or SNIP with management interface to perform\u003c/span\u003e\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAuthenticated (low privileged) remote code execution on Management Interface.\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e"
                }
              ],
              "value": "Improper Control of Generation of Code (\u0027Code Injection\u0027) in NetScaler ADC and NetScaler Gateway\u00a0allows an attacker with\u00a0access\u00a0to NSIP, CLIP or SNIP with management interface to perform\u00a0Authenticated (low privileged) remote code execution on Management Interface."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-18T01:12:54.917Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-6548",
        "datePublished": "2024-01-17T20:11:18.462Z",
        "dateReserved": "2023-12-06T11:01:54.643Z",
        "dateUpdated": "2025-10-21T23:05:28.157Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4967 (GCVE-0-2023-4967)

    Vulnerability from nvd โ€“ Published: 2023-10-27 18:01 โ€“ Updated: 2025-02-27 20:39
    VLAI
    Title
    Denial of service
    Summary
    Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-02-26 21:50 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    References
    Impacted products
    Vendor Product Version
    Cloud Software Group NetScaler ADC Affected: 14.1 , < 8.50 (patch)
    Affected: 13.1 , < 49.15 (patch)
    Affected: 13.0 , < 92.19 (patch)
    Affected: 13.1-FIPS , < 37.164 (patch)
    Affected: 12.1-FIPS , < 55.300 (patch)
    Affected: 12.1-NDcPP , < 55.300 (patch)
    Create a notification for this product.
    Cloud Software Group NetScaler Gateway Affected: 14.1 , < 8.50 (patch)
    Affected: 13.1 , < 49.15 (patch)
    Affected: 13.0 , < 92.19 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:44:53.479Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX579459/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4967",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-26T21:50:03.367350Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-27T20:39:19.338Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler ADC",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "8.50",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "49.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.19",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "37.164",
                  "status": "affected",
                  "version": "13.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.300",
                  "status": "affected",
                  "version": "12.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.300",
                  "status": "affected",
                  "version": "12.1-NDcPP",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler Gateway",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "8.50",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "49.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.19",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server"
                }
              ],
              "value": "Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-27T18:01:59.707Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX579459/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Denial of service",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-4967",
        "datePublished": "2023-10-27T18:01:59.707Z",
        "dateReserved": "2023-09-14T15:51:24.455Z",
        "dateUpdated": "2025-02-27T20:39:19.338Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-6184 (GCVE-0-2023-6184)

    Vulnerability from cvelistv5 โ€“ Published: 2024-01-18 01:04 โ€“ Updated: 2025-06-02 15:04
    VLAI Previdian
    Summary
    Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-05-08 15:53 UTC
    CWE
    • CWE-913 - Improper Control of Dynamically-Managed Code Resources
    Impacted products
    Vendor Product Version
    Cloud Software Group Citrix Session Recording Affected: 2311 Current Release , < 0 (patch)
    Affected: 1912 LTSR , < CU8 hotfix 19.12.8100.4 (patch)
    Affected: 2203 LTSR , < CU4 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:21:17.772Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX583930/citrix-session-recording-security-bulletin-for-cve20236184"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-08T15:53:46.961310Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-02T15:04:27.473Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix Session Recording",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "0",
                  "status": "affected",
                  "version": "2311 Current Release",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU8 hotfix 19.12.8100.4",
                  "status": "affected",
                  "version": "1912 LTSR ",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU4",
                  "status": "affected",
                  "version": "2203 LTSR",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting"
                }
              ],
              "value": "Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-913",
                  "description": "CWE-913 Improper Control of Dynamically-Managed Code Resources",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-18T01:04:15.120Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX583930/citrix-session-recording-security-bulletin-for-cve20236184"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-6184",
        "datePublished": "2024-01-18T01:04:15.120Z",
        "dateReserved": "2023-11-16T21:18:24.367Z",
        "dateUpdated": "2025-06-02T15:04:27.473Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5914 (GCVE-0-2023-5914)

    Vulnerability from cvelistv5 โ€“ Published: 2024-01-17 20:19 โ€“ Updated: 2025-06-17 21:19
    VLAI Previdian
    Summary
    Cross-site scripting (XSS)
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-18 01:07 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Cloud Software Group Citrix StoreFront Affected: 2308 Current Release , < 1 (patch)
    Affected: 2311 Current Release , < 0 (patch)
    Affected: 1912 LTSR , < CU8 hotfix 3.22.8001.2 (patch)
    Affected: 2203 LTSR , < CU4 Update 1 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:14:24.983Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX583759/citrix-storefront-security-bulletin-for-cve20235914"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5914",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-18T01:07:35.301720Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-17T21:19:18.814Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix StoreFront",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "1",
                  "status": "affected",
                  "version": "2308 Current Release",
                  "versionType": "patch"
                },
                {
                  "lessThan": "0",
                  "status": "affected",
                  "version": "2311 Current Release",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU8 hotfix 3.22.8001.2",
                  "status": "affected",
                  "version": "1912 LTSR",
                  "versionType": "patch"
                },
                {
                  "lessThan": "CU4 Update 1",
                  "status": "affected",
                  "version": "2203 LTSR ",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u0026nbsp; Cross-site scripting (XSS)"
                }
              ],
              "value": "\u00a0 Cross-site scripting (XSS)"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-17T20:19:49.869Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX583759/citrix-storefront-security-bulletin-for-cve20235914"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-5914",
        "datePublished": "2024-01-17T20:19:49.869Z",
        "dateReserved": "2023-11-01T22:55:27.290Z",
        "dateUpdated": "2025-06-17T21:19:18.814Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-6549 (GCVE-0-2023-6549)

    Vulnerability from cvelistv5 โ€“ Published: 2024-01-17 20:15 โ€“ Updated: 2025-10-21 23:05
    VLAI CISA Previdian
    Summary
    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service andย Out-Of-Bounds Memory Read
    SSVC
    Exploitation: active Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-31 05:00 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Cloud Software Group NetScaler ADC Affected: 14.1 , < 12.35 (patch)
    Affected: 13.1 , < 51.15 (patch)
    Affected: 13.0 , < 92.21 (patch)
    Affected: 13.1-FIPS , < 37.176 (patch)
    Affected: 12.1-FIPS , < 55.302 (patch)
    Affected: 12.1-NDcPP , < 55.302 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:35:13.934Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6549",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-31T05:00:20.477654Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-01-17",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6549"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:27.936Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6549"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-01-17T00:00:00.000Z",
                "value": "CVE-2023-6549 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler ADC",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "12.35",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "51.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.21",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "37.176",
                  "status": "affected",
                  "version": "13.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-NDcPP",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cb\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eImproper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and\u0026nbsp;\u003c/span\u003e\u003c/b\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cb\u003eOut-Of-Bounds Memory Read\u003c/b\u003e\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and\u00a0Out-Of-Bounds Memory Read"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-10T17:29:28.138Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-6549",
        "datePublished": "2024-01-17T20:15:53.345Z",
        "dateReserved": "2023-12-06T11:01:58.256Z",
        "dateUpdated": "2025-10-21T23:05:27.936Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-6548 (GCVE-0-2023-6548)

    Vulnerability from cvelistv5 โ€“ Published: 2024-01-17 20:11 โ€“ Updated: 2025-10-21 23:05
    VLAI CISA Previdian
    Summary
    Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gatewayย allows an attacker withย accessย to NSIP, CLIP or SNIP with management interface to performย Authenticated (low privileged) remote code execution on Management Interface.
    SSVC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-18 14:00 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Cloud Software Group NetScaler ADC Affected: 14.1 , < 12.35 (patch)
    Affected: 13.1 , < 51.15 (patch)
    Affected: 13.0 , < 92.21 (patch)
    Affected: 13.1-FIPS , < 37.176 (patch)
    Affected: 12.1-FIPS , < 55.302 (patch)
    Affected: 12.1-NDcPP , < 55.302 (patch)
    Create a notification for this product.
    Cloud Software Group NetScaler Gateway Affected: 14.1 , < 12.35 (patch)
    Affected: 13.1 , < 51.15 (patch)
    Affected: 13.0 , < 92.21 (patch)
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 14.1 , < 14.1-12.35 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1:*:*:*:-:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 13.1 , < 13.1-51.15 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:-:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 13.0 , < 13.0-92.21 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0:*:*:*:-:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 13.1 , < 13.1-37.176 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:fips:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 12.1 , < 12.1-55.302 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:fips:*:*:*
    Create a notification for this product.
    citrix netscaler_application_delivery_controller Affected: 12.1 , < 12.1-55.302 (custom)
        cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:ndcpp:*:*:*
    Create a notification for this product.
    citrix netscaler_gateway Affected: 14.1 , < 14.1-12.35 (custom)
        cpe:2.3:a:citrix:netscaler_gateway:14.1:*:*:*:*:*:*:*
    Create a notification for this product.
    citrix netscaler_gateway Affected: 13.1 , < 13.1-51.15 (custom)
        cpe:2.3:a:citrix:netscaler_gateway:13.1:*:*:*:*:*:*:*
    Create a notification for this product.
    citrix netscaler_gateway Affected: 13.0 , < 13.0-92.21 (custom)
        cpe:2.3:a:citrix:netscaler_gateway:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "14.1-12.35",
                    "status": "affected",
                    "version": "14.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.1-51.15",
                    "status": "affected",
                    "version": "13.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.0-92.21",
                    "status": "affected",
                    "version": "13.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:fips:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.1-37.176",
                    "status": "affected",
                    "version": "13.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:fips:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "12.1-55.302",
                    "status": "affected",
                    "version": "12.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:ndcpp:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_application_delivery_controller",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "12.1-55.302",
                    "status": "affected",
                    "version": "12.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_gateway:14.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_gateway",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "14.1-12.35",
                    "status": "affected",
                    "version": "14.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_gateway:13.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_gateway",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.1-51.15",
                    "status": "affected",
                    "version": "13.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:citrix:netscaler_gateway:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "netscaler_gateway",
                "vendor": "citrix",
                "versions": [
                  {
                    "lessThan": "13.0-92.21",
                    "status": "affected",
                    "version": "13.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6548",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-18T14:00:57.375485Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-01-17",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:28.157Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6548"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-01-17T00:00:00.000Z",
                "value": "CVE-2023-6548 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:35:14.029Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler ADC",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "12.35",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "51.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.21",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "37.176",
                  "status": "affected",
                  "version": "13.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.302",
                  "status": "affected",
                  "version": "12.1-NDcPP",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler Gateway",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "12.35",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "51.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.21",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eImproper Control of Generation of Code (\u0027Code Injection\u0027) in NetScaler ADC and NetScaler Gateway\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eallows an attacker with\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;access\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;to NSIP, CLIP or SNIP with management interface to perform\u003c/span\u003e\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAuthenticated (low privileged) remote code execution on Management Interface.\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e"
                }
              ],
              "value": "Improper Control of Generation of Code (\u0027Code Injection\u0027) in NetScaler ADC and NetScaler Gateway\u00a0allows an attacker with\u00a0access\u00a0to NSIP, CLIP or SNIP with management interface to perform\u00a0Authenticated (low privileged) remote code execution on Management Interface."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-18T01:12:54.917Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-6548",
        "datePublished": "2024-01-17T20:11:18.462Z",
        "dateReserved": "2023-12-06T11:01:54.643Z",
        "dateUpdated": "2025-10-21T23:05:28.157Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4967 (GCVE-0-2023-4967)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-27 18:01 โ€“ Updated: 2025-02-27 20:39
    VLAI
    Title
    Denial of service
    Summary
    Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-02-26 21:50 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    References
    Impacted products
    Vendor Product Version
    Cloud Software Group NetScaler ADC Affected: 14.1 , < 8.50 (patch)
    Affected: 13.1 , < 49.15 (patch)
    Affected: 13.0 , < 92.19 (patch)
    Affected: 13.1-FIPS , < 37.164 (patch)
    Affected: 12.1-FIPS , < 55.300 (patch)
    Affected: 12.1-NDcPP , < 55.300 (patch)
    Create a notification for this product.
    Cloud Software Group NetScaler Gateway Affected: 14.1 , < 8.50 (patch)
    Affected: 13.1 , < 49.15 (patch)
    Affected: 13.0 , < 92.19 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:44:53.479Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.citrix.com/article/CTX579459/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4967",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-26T21:50:03.367350Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-27T20:39:19.338Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler ADC",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "8.50",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "49.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.19",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "37.164",
                  "status": "affected",
                  "version": "13.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.300",
                  "status": "affected",
                  "version": "12.1-FIPS",
                  "versionType": "patch"
                },
                {
                  "lessThan": "55.300",
                  "status": "affected",
                  "version": "12.1-NDcPP",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NetScaler Gateway",
              "vendor": "Cloud Software Group",
              "versions": [
                {
                  "lessThan": "8.50",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "49.15",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                },
                {
                  "lessThan": "92.19",
                  "status": "affected",
                  "version": "13.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server"
                }
              ],
              "value": "Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-27T18:01:59.707Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/article/CTX579459/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Denial of service",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2023-4967",
        "datePublished": "2023-10-27T18:01:59.707Z",
        "dateReserved": "2023-09-14T15:51:24.455Z",
        "dateUpdated": "2025-02-27T20:39:19.338Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }