cvelist/2023/6xxx/CVE-2023-6548.json
2024-01-18 02:00:38 +00:00

136 lines
5.6 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2023-6548",
"ASSIGNER": "secure@citrix.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway\u00a0allows an attacker with\u00a0access\u00a0to NSIP, CLIP or SNIP with management interface to perform\u00a0Authenticated (low privileged) remote code execution on Management Interface."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-94 Improper Control of Generation of Code ('Code Injection')",
"cweId": "CWE-94"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Cloud Software Group",
"product": {
"product_data": [
{
"product_name": "NetScaler ADC\u202f",
"version": {
"version_data": [
{
"version_affected": "<",
"version_name": "14.1",
"version_value": "12.35"
},
{
"version_affected": "<",
"version_name": "13.1",
"version_value": "51.15"
},
{
"version_affected": "<",
"version_name": "13.0 ",
"version_value": "92.21"
},
{
"version_affected": "<",
"version_name": " 13.1-FIPS",
"version_value": "37.176"
},
{
"version_affected": "<",
"version_name": "12.1-FIPS",
"version_value": "55.302"
},
{
"version_affected": "<",
"version_name": "12.1-NDcPP",
"version_value": "55.302"
}
]
}
},
{
"product_name": "NetScaler Gateway",
"version": {
"version_data": [
{
"version_affected": "<",
"version_name": "14.1",
"version_value": "12.35"
},
{
"version_affected": "<",
"version_name": "13.1",
"version_value": "51.15"
},
{
"version_affected": "<",
"version_name": "13.0",
"version_value": "92.21"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549",
"refsource": "MISC",
"name": "https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549"
}
]
},
"generator": {
"engine": "Vulnogram 0.1.0-dev"
},
"source": {
"discovery": "UNKNOWN"
},
"impact": {
"cvss": [
{
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
}
]
}
}