CVE CVE

CVE-2025-6543

CISA Known Exploited Vulnerability (KEV)

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

June 30, 2025

July 21, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Weakness Enumeration

CWE-ID CWE Name

CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer

Known Affected Software Configurations


cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.176:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-51.15:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-12.35:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-51.15:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-12.35:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.0-92.19:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-49.15:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1-8.50:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:14.1:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.300:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.300:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0-92.19:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.164:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-49.15:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-8.50:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1-49.13:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.1:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.0-91.13:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:13.0:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-49.13:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1-37.159:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.1:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0-91.13:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:13.0:*:*:*:-:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.297:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:ndcpp:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1-55.297:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_application_delivery_controller:12.1:*:*:*:fips:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:11.1-65.20:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:12.1:*:*:*:*:*:*:*

cpe:2.3:a:citrix:netscaler_gateway:11.1:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined