CVE CVE

CVE-2025-5777

CISA Known Exploited Vulnerability (KEV)

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

July 10, 2025

July 11, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Weakness Enumeration

CWE-ID CWE Name

CWE-125
Out-of-bounds Read

CWE-457
Use of Uninitialized Variable

CWE-908
Use of Uninitialized Resource

Known Affected Software Configurations


cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.235:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.235:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-58.32:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-43.56:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-52.19:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-53.24:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-54.29:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-55.34:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-56.18:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-57.26:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-58.32:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-17.38:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-21.57:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-25.56:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-29.72:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-34.42:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-38.53:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-4.42:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-43.56:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.302:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.176:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-51.15:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-12.35:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-51.15:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-12.35:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.0-92.19:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-49.15:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-8.50:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.300:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.300:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0-92.19:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.164:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-49.15:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-8.50:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-49.13:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.0-91.13:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.0:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-49.13:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.159:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0-91.13:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.297:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.297:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:11.1-65.20:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:12.1:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:11.1:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
7.5
Severity:

HIGH

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2

Not defined