Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
A CWE-119 class error (buffer overflow) occurs in components handling VPN traffic when the device is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. Improper buffer boundary management allows unintended control flow, which can lead to both device destabilization and potential unauthorized code execution. The attack is possible remotely over the network without authentication, although it requires specific technical conditions to be met (AC:H, AT:P).
An attacker can cause denial of service (DoS) to the NetScaler device, and unintended control flow creates a risk of arbitrary code execution in the context of the network process. Consequences include unavailability of VPN services and potential compromise of data confidentiality and integrity.
Immediately apply patches available from the vendor in accordance with references published in Citrix article CTX694788 (https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788). Until the patch is deployed, consider restricting access to VPN and AAA interfaces to trusted networks only.
Citrix NetScaler ADC and Citrix NetScaler Gateway configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Specific versions are indicated in vendor references (CTX694788).
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCitrix Netscaler Application Delivery Controller
APPCitrix13.1 – 13.1-37.236 (excl.)13.1 – 13.1-59.19 (excl.)14.1 – 14.1-47.46 (excl.)Citrix Netscaler Gateway
APPCitrix13.1 – 13.1-59.19 (excl.)14.1 – 14.1-47.46 (excl.)
CISA KEV — detailsi
- Vendori
- Citrix ↗
- Producti
- NetScaler ADC and Gateway
- Added to KEVi
- June 30, 2025
- Remediation deadline (US Federal)i
- July 21, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Related vulnerabilities
Citrix NetScaler ADC/Gateway — memory overread przez SAML IDP
Przepełnienie pamięci w Citrix NetScaler ADC i Gateway — RCE/DoS
CitrixBleed 2 — memory overread w Citrix NetScaler ADC i Gateway
Citrix Bleed – wyciek tokenów sesji w NetScaler ADC i Gateway
Nieuwierzytelniony RCE w Citrix NetScaler ADC i Gateway