CVE-2023-6549: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2024-01-17. EPSS: 57.6% chance of exploitation in the next 30 days.

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

Affected products

  • Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.302 (fixed in 12.1-55.302); from 13.0, before 13.0-92.21 (fixed in 13.0-92.21); from 13.1, before 13.1-37.176 (fixed in 13.1-37.176); from 13.1, before 13.1-51.15 (fixed in 13.1-51.15); from 14.1, before 14.1-12.35 (fixed in 14.1-12.35)
  • Citrix NetScaler Gateway: from 13.0, before 13.0-92.21 (fixed in 13.0-92.21); from 13.1, before 13.1-51.15 (fixed in 13.1-51.15); from 14.1, before 14.1-12.35 (fixed in 14.1-12.35)

Published 2024-01-17. Last modified 2026-06-17.