# N/A
## 概述
在NetScaler ADC和NetScaler Gateway中存在内存缓冲区操作限制不当的问题,这允许未认证的拒绝服务攻击和内存越界读取。
## 影响版本
未提供具体影响版本信息。
## 细节
该漏洞源于内存缓冲区操作限制不当,导致未认证用户可能发起拒绝服务攻击并进行内存越界读取。
## 影响
该漏洞允许未认证的攻击者造成服务中断(拒绝服务)并读取内存越界数据,这可能导致系统不稳定性和敏感信息泄露。
                                        
                                    
                                | # | POC 描述 | 源链接 | 神龙链接 | 
|---|---|---|---|
| 1 | The vulnerability would enable an attacker to remotely obtain sensitive information from a NetScaler appliance configured as a Gateway or AAA virtual server via a very commonly connected Web interface, and without requiring authentication. This bug is nearly identical to the Citrix Bleed vulnerability (CVE-2023-4966), except it is less likely to return highly sensitive information to an attacker. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6549.yaml | POC详情 | 
暂无评论