Citrix Releases Security Updates for NetScaler ADC and Gateway - 20230719001¶
Overview¶
Citrix has released security updates to address vulnerabilities (CVE-2023-3519, CVE-2023-3466, and CVE-2023-3467) affecting NetScaler ADC and NetScaler Gateway. An attacker can exploit one of these vulnerabilities to take control of an affected system. According to Citrix, CVE-2023-3519 is being exploited on unmitigated appliances.
What is vulnerable?¶
The vulnerability affects the following products:
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13
- NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.13
- NetScaler ADC 13.1-FIPS before 13.1-37.159
- NetScaler ADC 12.1-FIPS before 12.1-55.297
- NetScaler ADC 12.1-NDcPP before 12.1-55.297
What has been observed?¶
There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing
Recommendation¶
The WA SOC recommends users and administrators to review the Citrix security bulletin and apply the necessary updates.