Systems Engineering is aware of the vulnerabilities recently found in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Exploits on unmitigated appliances have been observed.
Citrix rates these vulnerabilities as HIGH
Citrix has released a security bulletin addressing two (2) vulnerabilities: CVE-2023-6548, and CVE-2023-6549. These vulnerabilities could potentially allow an attacker to gain unauthorized access to sensitive information or execute arbitrary code on affected systems.
The following supported versions of NetScaler are impacted:
Note: NetScaler ADC and NetScaler Gateway version 12.1 is now End Of Life (EOL) and is vulnerable.
Systems Engineering is proactively patching clients subscribed to SE Platform and NetAdmin services, that have NetScaler's in their compute environment. Due to the zero-day nature of the vulnerability, the work involved in patching is not covered under service contracts.
For all other clients, we strongly recommend you update impacted systems with the latest security patches as soon as possible. Citrix has provided instructions in their security advisory here.
If you are a Systems Engineering client and have questions about this Security Alert, please contact your Account Manager.