Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
When a NetScaler device operates as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, insufficient input validation allows reading memory areas beyond the intended buffer (CWE-125). The memory may contain uninitialized or residual data from previous operations (CWE-908, CWE-457), which could expose sensitive information to an attacker without requiring authentication.
An unauthenticated remote attacker can read process memory contents, potentially gaining access to sensitive data such as session tokens, credentials, or other information processed by the device.
Patches available from the manufacturer must be applied immediately in accordance with Citrix bulletin CTX693420. CISA has set an extremely short deadline for federal agencies to implement patches, indicating the critical nature of the threat. Until updates are applied, consider restricting access to management interfaces and VPN gateways exclusively to trusted networks.
Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server — specific versions indicated in manufacturer references (CTX693420).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCitrix Netscaler Application Delivery Controller
APPCitrix12.1 – 12.1-55.328 (excl.)13.1 – 13.1-37.235 (excl.)13.1 – 13.1-58.32 (excl.)14.1 – 14.1-43.56 (excl.)Citrix Netscaler Gateway
APPCitrix13.1 – 13.1-58.32 (excl.)14.1 – 14.1-43.56 (excl.)
CISA KEV — detailsi
- Vendori
- Citrix ↗
- Producti
- NetScaler ADC and Gateway
- Added to KEVi
- July 10, 2025
- Remediation deadline (US Federal)i
- July 11, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Related vulnerabilities
Citrix NetScaler ADC/Gateway — memory overread przez SAML IDP
Przepełnienie pamięci w Citrix NetScaler ADC i Gateway — RCE/DoS
Przepełnienie pamięci w Citrix NetScaler ADC i Gateway – RCE/DoS przez VPN
Citrix Bleed – wyciek tokenów sesji w NetScaler ADC i Gateway
Nieuwierzytelniony RCE w Citrix NetScaler ADC i Gateway