By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds Two Critical Citrix NetScaler Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Sunday, March 10, 2024, that it has added two critical vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Gateway products to its Known Exploited Vulnerabilities (KEV) catalog. This addition signifies that these flaws are currently being actively exploited by malicious actors in the wild, posing a significant and immediate threat to organizations worldwide. The inclusion in the KEV catalog mandates federal agencies to patch these vulnerabilities within a specified timeframe to mitigate potential cyberattacks. The two vulnerabilities are identified as CVE-2023-35193 and CVE-2023-34658. CVE-2023-35193, with a CVSS score of 9.5, is an unauthenticated arbitrary code execution vulnerability. This means an attacker, without needing any prior access or credentials, can execute malicious code on the affected NetScaler instances. Such an exploit could allow attackers to gain complete control over the compromised system, steal sensitive data, or deploy further malware. CVE-2023-34658, rated with a CVSS score of 8.4, is an authentication bypass vulnerability. This flaw enables attackers to circumvent the normal authentication mechanisms, potentially gaining unauthorized access to protected resources or administrative functions within the NetScaler environment. The active exploitation of these vulnerabilities has been reported, prompting CISA's urgent action. Citrix, the vendor of NetScaler, had previously released security advisories and updates to address these issues. The NetScaler ADC and Gateway are widely used by enterprises to manage and secure network traffic, application delivery, and remote access. Their compromise can therefore have far-reaching consequences, impacting the availability and security of critical business applications and services. Organizations utilizing these Citrix products are strongly advised to review the security advisories from Citrix and CISA, and to apply the necessary patches and workarounds immediately. The KEV catalog serves as a critical resource for cybersecurity professionals, highlighting vulnerabilities that pose the greatest risk due to active exploitation, and guiding remediation efforts to protect against widespread attacks. The inclusion of these two NetScaler flaws underscores the ongoing threat landscape and the importance of proactive vulnerability management and timely patching of network infrastructure components.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.