CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2025-5777

CVSS 9.3v4.0pub. 2025-06-17upd. 2026-08-04

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

🤖 AI Analysis
How it works

When a NetScaler device operates as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, insufficient input validation allows reading memory areas beyond the intended buffer (CWE-125). The memory may contain uninitialized or residual data from previous operations (CWE-908, CWE-457), which could expose sensitive information to an attacker without requiring authentication.

Impact

An unauthenticated remote attacker can read process memory contents, potentially gaining access to sensitive data such as session tokens, credentials, or other information processed by the device.

Mitigation & patch

Patches available from the manufacturer must be applied immediately in accordance with Citrix bulletin CTX693420. CISA has set an extremely short deadline for federal agencies to implement patches, indicating the critical nature of the threat. Until updates are applied, consider restricting access to management interfaces and VPN gateways exclusively to trusted networks.

Who is affected

Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server — specific versions indicated in manufacturer references (CTX693420).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Citrix Netscaler Application Delivery Controller

    APP
    Citrix
    12.1 – 12.1-55.328 (excl.)13.1 – 13.1-37.235 (excl.)13.1 – 13.1-58.32 (excl.)14.1 – 14.1-43.56 (excl.)
  • Citrix Netscaler Gateway

    APP
    Citrix
    13.1 – 13.1-58.32 (excl.)14.1 – 14.1-43.56 (excl.)

CISA KEV — detailsi

Vendori
Citrix
Producti
NetScaler ADC and Gateway
Added to KEVi
July 10, 2025
Remediation deadline (US Federal)i
July 11, 2025(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 11 lipca 2025
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2026-3055CRITICAL9.3⚠ KEVPL ✓same product

Citrix NetScaler ADC/Gateway — memory overread przez SAML IDP

CVE-2025-7775CRITICAL9.2⚠ KEVPL ✓same product

Przepełnienie pamięci w Citrix NetScaler ADC i Gateway — RCE/DoS

CVE-2025-6543CRITICAL9.2⚠ KEVPL ✓same product

Przepełnienie pamięci w Citrix NetScaler ADC i Gateway – RCE/DoS przez VPN

CVE-2023-4966CRITICAL9.4⚠ KEVPL ✓same product

Citrix Bleed – wyciek tokenów sesji w NetScaler ADC i Gateway

CVE-2023-3519CRITICAL9.8⚠ KEVPL ✓same product

Nieuwierzytelniony RCE w Citrix NetScaler ADC i Gateway